Skip to content

fix: add snyk-bot to the shared CLA allowlist - #64

Closed
martyna-mindsdb wants to merge 1 commit into
mainfrom
martyna/cla-allowlist-snyk-bot
Closed

martyna-mindsdb wants to merge 1 commit into
mainfrom
martyna/cla-allowlist-snyk-bot

Conversation

@martyna-mindsdb

Copy link
Copy Markdown
Contributor

Summary

snyk-bot opens automated dependency-upgrade PRs across many repos in the org (cowork-server, cowork, mindshub, auth, mindshub_frontend, mindshub_inference, anton, ...). Like dependabot[bot] and mindsdb-release-train[bot], it can't post the CLA sign-off sentence itself — so any PR that later needs a human commit added on top of its original snyk-bot commit (a merge-conflict resolution, a review fix) gets permanently stuck: CLAssistant reports "N-1 out of N committers signed" with no way to close the gap. Hit directly on mindsdb/anton#443.

Fix

Add snyk-bot to the shared workflow's default allowlist, per this file's own header comment: the allowlist lives here (not per-repo) specifically so recurring org-wide bots are handled once rather than drifting across repo-level overrides. snyk-bot opening PRs org-wide is exactly that case, not a one-off.

Verification

  • Confirmed the exact login via mindsdb/anton#443's commit history: snyk-bot (case-sensitive, matches the action's exact-match rule noted in this file's own header).
  • Grepped the repo for any other place the old two-bot list is referenced — none found; this is the single source of truth.

🤖 Generated with Claude Code

snyk-bot opens automated dependency-upgrade PRs across many repos in
the org (cowork-server, cowork, mindshub, auth, mindshub_frontend,
mindshub_inference, anton, ...). Same as dependabot[bot] and
mindsdb-release-train[bot], it can't post the sign-off sentence
itself, so any PR that ends up needing a human commit added on top of
its original snyk-bot commit (a merge-conflict resolution, a review
fix) is permanently stuck: CLAssistant reports "N-1 out of N
committers signed" with no way to close the gap (mindsdb/anton#443
hit this directly).

Per this file's own header: the allowlist lives here because it's
bots, not people, and edited here rather than per-repo so it doesn't
drift. snyk-bot opening PRs org-wide is exactly the "not a one-off"
case that belongs in the shared default rather than a per-repo
allowlist override.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@martyna-mindsdb
martyna-mindsdb requested a review from a team September 8, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant