Is there an existing issue for this?
Current Behavior
The cla job in .github/workflows/contrib.yaml runs contributor-assistant/github-action with the default lock-pullrequest-aftermerge: true. The action locks the pull request on the closed event, regardless of whether the PR was merged or just closed.
Because contrib.yaml also triggers on reopened, closing and reopening a PR puts it into a state the contributor cannot escape:
closed fires. The action locks the PR. Job succeeds.
reopened fires. The action tries to create or update its CLA comment. The PR is now locked, so the write fails and the job errors out.
From that point on the cla check fails on every subsequent run, because the action always needs to write a comment and the lock is never lifted. The failure is unrelated to whether the CLA is actually signed. Only a repository admin can unlock, so the PR author cannot recover.
This also blocks the documented recheck escape hatch, since the lock prevents the contributor from commenting at all.
Relevant Log Output
# Run 30312572901, triggered by `closed` at 22:58:17Z, conclusion: success
CLA Assistant GitHub Action bot has started the process
Locking the Pull Request to safe guard the Pull Request CLA Signatures
successfully locked the pull request 27499
# Run 30312578189, triggered by `reopened` at 22:58:33Z, conclusion: failure
CLA Assistant GitHub Action bot has started the process
##[error]Could not update the JSON file: Error occured when creating or editing
the comments of the pull request: Error occured when updating the pull request
comment: Unable to create comment because issue is locked.
Expected Behavior
Closing and reopening a pull request should not permanently break the cla check.
A few options:
- Set
lock-pullrequest-aftermerge: false, since the job runs on closed and cannot distinguish merged from closed.
- Gate the
cla job so it does not run on the closed action.
- Unlock the PR when the
reopened action fires.
Steps to Reproduce
- Open a pull request as an external contributor who has not yet signed the CLA.
- Sign the CLA. The signature is recorded in
coder/cla.
- Close the pull request, then reopen it to force a re-run of the check.
- The
closed run locks the PR. The reopened run fails with Unable to create comment because issue is locked.
- The
cla check now fails permanently and the contributor cannot unlock or comment.
Environment
- Host OS: n/a (GitHub Actions, ubuntu-24.04)
- Coder version: n/a (repository CI)
Additional Context
The issue occurs consistently
This is currently affecting #27499. The CLA is signed and valid: the signature for Amadeus-22 (id 156959341) is recorded in coder/cla at v2022-09-04/signatures.json, and run 30312572901 confirms the check passed before the lock took effect. The only remaining failure is the locked-comment error above.
Could a maintainer unlock #27499? Once unlocked, a push to the branch should re-trigger contrib and let the cla check pass. I cannot comment on that PR to ask there, which is why I am opening this issue instead.
Is there an existing issue for this?
Current Behavior
The
clajob in.github/workflows/contrib.yamlrunscontributor-assistant/github-actionwith the defaultlock-pullrequest-aftermerge: true. The action locks the pull request on theclosedevent, regardless of whether the PR was merged or just closed.Because
contrib.yamlalso triggers onreopened, closing and reopening a PR puts it into a state the contributor cannot escape:closedfires. The action locks the PR. Job succeeds.reopenedfires. The action tries to create or update its CLA comment. The PR is now locked, so the write fails and the job errors out.From that point on the
clacheck fails on every subsequent run, because the action always needs to write a comment and the lock is never lifted. The failure is unrelated to whether the CLA is actually signed. Only a repository admin can unlock, so the PR author cannot recover.This also blocks the documented
recheckescape hatch, since the lock prevents the contributor from commenting at all.Relevant Log Output
Expected Behavior
Closing and reopening a pull request should not permanently break the
clacheck.A few options:
lock-pullrequest-aftermerge: false, since the job runs onclosedand cannot distinguish merged from closed.clajob so it does not run on theclosedaction.reopenedaction fires.Steps to Reproduce
coder/cla.closedrun locks the PR. Thereopenedrun fails withUnable to create comment because issue is locked.clacheck now fails permanently and the contributor cannot unlock or comment.Environment
Additional Context
The issue occurs consistently
This is currently affecting #27499. The CLA is signed and valid: the signature for
Amadeus-22(id156959341) is recorded incoder/claatv2022-09-04/signatures.json, and run 30312572901 confirms the check passed before the lock took effect. The only remaining failure is the locked-comment error above.Could a maintainer unlock #27499? Once unlocked, a push to the branch should re-trigger
contriband let theclacheck pass. I cannot comment on that PR to ask there, which is why I am opening this issue instead.