Anso
b9ada7f50b
fix(ci): disable CLA Assistant PR auto-lock so release-please can comment ( #890 )
...
The contributor-assistant action defaults to locking merged PRs to
"safeguard CLA signatures", but signatures are stored in
signatures/version1/cla.json and need no extra protection. The auto-lock
fires within seconds of merge and blocks release-please from posting its
"included in vX.Y.Z" comment on the merged release PR, failing the
release-please workflow on every release (0.67.1, 0.68.0).
2026-05-03 00:07:32 -04:00
dependabot[bot]
cb0161b77e
chore(deps): bump contributor-assistant/github-action ( #844 )
...
Bumps the all-actions group with 1 update in the / directory: [contributor-assistant/github-action](https://github.com/contributor-assistant/github-action ).
Updates `contributor-assistant/github-action` from 2.3.1 to 2.6.1
- [Release notes](https://github.com/contributor-assistant/github-action/releases )
- [Commits](https://github.com/contributor-assistant/github-action/compare/a895a435fcce79ecf28fbce61a4ef0f0dabc9853...ca4a40a7d1004f18d9960b404b97e5f30a505a08 )
---
updated-dependencies:
- dependency-name: contributor-assistant/github-action
dependency-version: 2.6.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: all-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-29 16:32:22 -04:00
Anso
9274584255
chore: migration heartbeat - verify CI ( #847 )
...
* chore: migration heartbeat - verify CI and GitHub App sync
* chore: add AnsoCode to CLA allowlist
2026-04-29 15:52:23 -04:00
SaelixCode
3da0aa6036
chore: migrate repository URLs from AnsoCode/Sencho to studio-saelix/sencho
...
Updates all hardcoded GitHub repository references across 21 files:
- package.json: repository URL, bugs URL, homepage, description, author
- CONTRIBUTING.md: bug report template URL
- SECURITY.md: advisory URL, cosign cert-identity regexp
- .github/CODEOWNERS: @AnsoCode -> @studio-saelix/maintainers
- .github/workflows/ci.yml: repositories scope (Sencho -> sencho), docs-sync git URL
- .github/workflows/cla.yml: path-to-document URL
- .github/workflows/docker-publish.yml: cosign verify comment
- frontend/**/*.tsx: issues and changelog links (3 components)
- frontend/public/.well-known/security.txt: Contact and Policy URLs
- security/vex/sencho.openvex.json: @id field
- docs/openapi.yaml: license URL
- docs/docs.json: navbar and footer GitHub links (5 instances)
- docs/security.mdx: advisory and SECURITY.md links
- docs/reference/verifying-images.mdx: repo link + cosign regexp + legacy identity note
- docs/reference/contact.mdx: issues, LICENSE, advisory, policy, CoC links
- docs/reference/security-advisories.mdx: releases link
- docs/operations/verifying-images.mdx: cosign regexps and VEX download URL (6 instances)
- docs/operations/upgrade.mdx: releases links (2 instances)
- backend/src/utils/version-check.ts: GitHub Releases API endpoint
CHANGELOG.md intentionally excluded (release-please managed).
Legacy cosign identity note added for pre-migration image verification.
2026-04-29 09:24:20 -04:00
SaelixCode
c8287e43a0
chore(cla): add sencho-quartermaster[bot] to allowlist
2026-04-29 01:49:30 -04:00
SaelixCode
9d69ae73fc
chore(cla): add bots to allowlist
2026-04-29 01:47:30 -04:00
Anso
f788384b01
docs: update README header, revise CONTRIBUTING tier policy, add CLA ( #838 )
...
* docs: update README header, revise CONTRIBUTING tier policy, add CLA
* ci(github): pin CLA Assistant action to commit SHA
2026-04-29 01:31:36 -04:00