From b85a36d5545720297750f93bae2cdec8699a5a5e Mon Sep 17 00:00:00 2001 From: martyna-mindsdb Date: Tue, 8 Sep 2026 14:16:04 +0200 Subject: [PATCH] fix: add snyk-bot to the shared CLA allowlist snyk-bot opens automated dependency-upgrade PRs across many repos in the org (cowork-server, cowork, mindshub, auth, mindshub_frontend, mindshub_inference, anton, ...). Same as dependabot[bot] and mindsdb-release-train[bot], it can't post the sign-off sentence itself, so any PR that ends up needing a human commit added on top of its original snyk-bot commit (a merge-conflict resolution, a review fix) is permanently stuck: CLAssistant reports "N-1 out of N committers signed" with no way to close the gap (mindsdb/anton#443 hit this directly). Per this file's own header: the allowlist lives here because it's bots, not people, and edited here rather than per-repo so it doesn't drift. snyk-bot opening PRs org-wide is exactly the "not a one-off" case that belongs in the shared default rather than a per-repo allowlist override. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/cla-assistant.yml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/workflows/cla-assistant.yml b/.github/workflows/cla-assistant.yml index 3792724..9fc5374 100644 --- a/.github/workflows/cla-assistant.yml +++ b/.github/workflows/cla-assistant.yml @@ -59,9 +59,11 @@ # was a former colleague still exempt from signing. # # Bots stay, because a bot cannot sign: it cannot post the agreement sentence, -# so with no exemption its pull request is red forever. Only the two that -# actually open pull requests here are listed. `github-actions[bot]` needs no -# entry, since the action filters user id 41898282 in `graphql.ts` itself. +# so with no exemption its pull request is red forever. Only the three that +# actually open pull requests here are listed (`snyk-bot` opens automated +# dependency-upgrade PRs across many repos in the org). `github-actions[bot]` +# needs no entry, since the action filters user id 41898282 in `graphql.ts` +# itself. # # Add a bot by editing the default below, not by passing the input. Anything # passed per repo drifts, which is the whole reason this moved. @@ -85,7 +87,7 @@ on: allowlist: description: "Comma-separated logins exempt from signing. Bots only; see the header. Override only for a genuine one-off." type: string - default: 'dependabot[bot], mindsdb-release-train[bot]' + default: 'dependabot[bot], mindsdb-release-train[bot], snyk-bot' path-to-signatures: description: "Signature ledger path inside the calling repo" type: string