Skip to content

Conversation

@therealmarv
Copy link
Contributor

@therealmarv therealmarv commented Sep 17, 2025

see https://openstax.atlassian.net/browse/OTTER-303

  • CLA placeholder is added
  • add GH CI workflow for signing CLA

What's missing:

  • CLA final (needs some more time from legal I guess...)

Will not be implemented (but open for discussion):

  • Excluding SI devs group is possible (proof of concept here but it is failing because one permission missing) but requires a new safeinsights GitHub app with permission member org read! That permission is not available on a normal GitHub CI action but can be minted with an installed safeinsights GH app. Instructions on how to create and use such a Github app are described here

With this workflow inside this PR the SI devs also have to sign the CLA once.

@nathanstitt
Copy link
Member

@therealmarv I think you'll need to pull in main to get trivy to pass, #371 updated packages

@github-actions
Copy link

github-actions bot commented Oct 1, 2025

Total coverage

Lines Branches Functions Statements
99.46% (+0.00%) 66.62% (+0.00%) 97.09% (+0.00%) 99.47% (+0.00%)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants