Skip to content

chore(deps): bump openmls_rust_crypto from 0.4.4 to 0.6.0 #1438

chore(deps): bump openmls_rust_crypto from 0.4.4 to 0.6.0

chore(deps): bump openmls_rust_crypto from 0.4.4 to 0.6.0 #1438

Workflow file for this run

name: CLA Assistant

Check warning on line 1 in .github/workflows/cla.yml

View workflow run for this annotation

GitHub Actions / CLA Assistant

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
on:
issue_comment:
types: [created]
pull_request_target:
types: [opened, closed, synchronize]
# CLA Assistant Lite needs to comment on PRs and write to the
# `cla-signatures` branch where signatures are recorded. `actions: write`
# is required by contributor-assistant/github-action v2.x — without it the
# job hits "Resource not accessible by integration" after recognising
# signatures, leaving the PR check stuck on failure even though the CLA is
# satisfied.
permissions:
actions: write
contents: write
pull-requests: write
statuses: write
jobs:
CLAAssistant:
# Job-level guard so `issue_comment` events that aren't the magic strings
# don't spin up a runner just to skip the only step.
if: |
github.event_name == 'pull_request_target' ||
github.event.comment.body == 'recheck' ||
github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA'
runs-on: ubuntu-latest
steps:
- name: "CLA Assistant"
# Pinned to the immutable SHA of v2.6.1. `pull_request_target` runs with
# the base repo's GITHUB_TOKEN, so a moved tag would be a repo-takeover
# vector. Bump by replacing the SHA and updating the trailing comment.
uses: contributor-assistant/github-action@ca4a40a7d1004f18d9960b404b97e5f30a505a08 # v2.6.1
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
path-to-signatures: "signatures/version1/cla.json"
# Pinned to the immutable tag `cla-v1.1`, which freezes the agreed CLA
# text at a specific revision. A bare commit SHA is unsafe here: PRs are
# squash-merged, so a feature-branch commit is orphaned from main and
# 404s once its branch is pruned (exactly what happened to the previous
# c1193863 pin). A tag stays reachable regardless of merge strategy or
# branch cleanup. If you amend CLA.md, cut a NEW tag (cla-v1.2) on the
# amending commit and bump this ref in the same commit — never move an
# existing CLA tag; contributors have signed against it.
path-to-document: "https://github.com/Offline-Protocol/offline-protocol-sdk/blob/cla-v1.1/CLA.md"
# Signatures are committed to this branch — leave it unprotected.
branch: "cla-signatures"
# Allowlist GitHub App bot accounts (they have a "[bot]" suffix on the
# login). Do NOT use a bare "bot*" glob — it matches any human user
# whose login starts with "bot" and would let them skip the CLA.
allowlist: dependabot[bot],renovate[bot]