Repository navigation
M3 + orgs-import release - prod - #5240
Conversation
Signed-off-by: Łukasz Gryglicki <lgryglicki@cncf.io> Assisted by [OpenAI](https://platform.openai.com/) Assisted by [GitHub Copilot](https://github.com/features/copilot) Assisted by [Claude](https://claude.ai)
Signed-off-by: Łukasz Gryglicki <lgryglicki@cncf.io> Assisted by [OpenAI](https://platform.openai.com/) Assisted by [GitHub Copilot](https://github.com/features/copilot) Assisted by [Claude](https://claude.ai)
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Signed-off-by: Łukasz Gryglicki <lgryglicki@cncf.io> Assisted by [OpenAI](https://platform.openai.com/) Assisted by [GitHub Copilot](https://github.com/features/copilot) Assisted by [Claude](https://claude.ai)
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Company-selection behavior can direct signing and employee prechecks to the wrong internal company record.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Prepares EasyCLA’s M3 organization-management and organization-import changes for production.
Changes:
- Extends organization, signing, manager, and contributor APIs with supporting tests.
- Adds organization-import migration helpers, reporting, and configuration.
- Updates dependencies, operational tooling, and milestone documentation.
| File | Description |
|---|---|
| utils/self_serve_request_corporate_signature.sh | Adds corporate-signing request helper. |
| utils/company_cla_groups.sh | Adds organization CLA-group query helper. |
| utils/check_repos_synced.sh | Adds optional sibling-repository discovery. |
| utils/auth0.secret.example | Documents local credential configuration. |
| tests/functional/cypress/e2e/v1/company.cy.ts | Expects retired endpoint’s 410 response. |
| specs/001-easycla-ss-integration-fable/spec.md | Clarifies planned milestone scope. |
| specs/001-easycla-ss-integration-fable/m1-my-cla/contracts/upstream-easycla-api.md | Removes consolidated contract document. |
| specs/001-easycla-ss-integration-fable/checklists/requirements.md | Removes specification checklist. |
| specs/001-easycla-ss-integration-fable/05-milestone-k8s-v2-api-fable.md | Marks M5 as unplanned. |
| specs/001-easycla-ss-integration-fable/04-milestone-project-lens-pcc-fable.md | Marks M4 as unplanned. |
| specs/001-easycla-ss-integration-fable/03-milestone-ccla-org-lens-fable.md | Updates M3 progress and scope. |
| specs/001-easycla-ss-integration-fable/02-milestone-sign-cla-fable.md | Clarifies shipped actions and auditing. |
| specs/001-easycla-ss-integration-fable/01-milestone-read-only-me-lens-fable.md | Consolidates M1 implementation documentation. |
| specs/001-easycla-ss-integration-fable/00-overview-fable.md | Updates scope and deployment caveats. |
| README.md | Adds badge-line punctuation. |
| docs/easycla-ss-migration/README.md | Updates architecture reading order. |
| docs/easycla-ss-migration/m3-org-cleanup.md | Adds organization-cleanup runbook. |
| docs/contributor-api.md | Clarifies employee acknowledgment terminology. |
| CLAUDE.md | Documents memory-limited lint execution. |
| cla-backend-legacy/internal/store/companies.go | Adds deterministic external-ID company lookup. |
| cla-backend-legacy/internal/store/companies_test.go | Tests parent-company selection. |
| cla-backend-legacy/internal/api/handlers_employee_signature_test.go | Tests Salesforce company-ID acceptance. |
| cla-backend-legacy/internal/api/handlers_company_test.go | Tests unconditional company-creation retirement. |
| cla-backend-legacy/go.mod | Updates legacy backend dependencies. |
| cla-backend-go/v2/signatures/handlers_approval_test.go | Tests approval-update response handling. |
| cla-backend-go/v2/signatures/corporate_contributors_test.go | Tests contributor conversion and CSV export. |
| cla-backend-go/v2/sign/helpers.go | Standardizes acknowledgment wording. |
| cla-backend-go/v2/sign/handlers.go | Returns typed sanctions responses. |
| cla-backend-go/v2/organization-service/client.go | Adds username-based role assignment. |
| cla-backend-go/v2/my_clas/handlers.go | Forwards pagination and exports caller verification. |
| cla-backend-go/v2/my_clas/handlers_test.go | Tests pagination forwarding. |
| cla-backend-go/v2/events/handlers.go | Resolves persisted or virtual companies. |
| cla-backend-go/v2/events/handlers_test.go | Tests company resolution and authorization. |
| cla-backend-go/v2/dynamo_events/signatures.go | Indexes auto-created employee acknowledgments. |
| cla-backend-go/v2/company/handlers.go | Adds CLA-group listing and project-not-found handling. |
| cla-backend-go/v2/cla_search/service.go | Includes covered projects in search results. |
| cla-backend-go/v2/cla_search/service_test.go | Tests covered-project results and ordering. |
| cla-backend-go/v2/cla_manager/service.go | Extends manager services and company resolution. |
| cla-backend-go/v2/acs-service/org_grants.go | Adds paginated organization-grant retrieval. |
| cla-backend-go/v2/acs-service/org_grants_test.go | Tests grant pagination and failures. |
| cla-backend-go/utils/sanctions.go | Adds shared sanctions checks and responses. |
| cla-backend-go/utils/paging.go | Adds optional list-pagination bounds. |
| cla-backend-go/utils/paging_test.go | Tests pagination boundaries. |
| cla-backend-go/utils/constants.go | Corrects acknowledgment comment spelling. |
| cla-backend-go/swagger/common/signature.yaml | Corrects acknowledgment and approval-list descriptions. |
| cla-backend-go/swagger/common/signature-summary.yaml | Standardizes acknowledgment terminology. |
| cla-backend-go/swagger/common/self-serve-corporate-signature-output.yaml | Defines corporate-signing response identifiers. |
| cla-backend-go/swagger/common/self-serve-corporate-signature-input.yaml | Defines corporate-signing inputs and attestations. |
| cla-backend-go/swagger/common/properties/company-id.yaml | Allows internal UUIDs or Salesforce IDs. |
| cla-backend-go/swagger/common/prepare-sign.yaml | Clarifies employee-signing descriptions. |
| cla-backend-go/swagger/common/my-identity-list.yaml | Adds total identity count. |
| cla-backend-go/swagger/common/my-cla.yaml | Clarifies acknowledgment and status descriptions. |
| cla-backend-go/swagger/common/my-cla-manager.yaml | Updates acknowledgment terminology. |
| cla-backend-go/swagger/common/my-cla-manager-request.yaml | Clarifies email-only manager requests. |
| cla-backend-go/swagger/common/my-cla-manager-request-result.yaml | Clarifies acknowledgment identifier description. |
| cla-backend-go/swagger/common/my-cla-manager-list.yaml | Adds total manager count. |
| cla-backend-go/swagger/common/my-cla-list.yaml | Adds total agreement count. |
| cla-backend-go/swagger/common/ecla-invalidation-input.yaml | Defines optional invalidation metadata. |
| cla-backend-go/swagger/common/ecla-invalidate-result.yaml | Defines invalidated acknowledgment identifiers. |
| cla-backend-go/swagger/common/corporate-signature.yaml | Corrects approval-list descriptions. |
| cla-backend-go/swagger/common/corporate-contributor.yaml | Adds GitLab identity and invalidation fields. |
| cla-backend-go/swagger/common/company.yaml | Supports virtual-company identifiers. |
| cla-backend-go/swagger/common/company-cla-groups.yaml | Defines paginated organization CLA-group lists. |
| cla-backend-go/swagger/common/company-cla-group.yaml | Defines signing-entity CLA-group details. |
| cla-backend-go/swagger/common/company-cla-group-project.yaml | Defines covered-project details. |
| cla-backend-go/swagger/common/company-cla-group-manager.yaml | Defines manager identity details. |
| cla-backend-go/swagger/common/cla-search-result.yaml | Adds covered projects to search schema. |
| cla-backend-go/swagger/common/cla-manager-request.yaml | Defines manager-access request details. |
| cla-backend-go/swagger/common/cla-manager-request-list.yaml | Defines paginated manager-access requests. |
| cla-backend-go/swagger/cla.v1.yaml | Standardizes acknowledgment terminology. |
| cla-backend-go/signatures/projections.go | Adds invalidation-aware database projection. |
| cla-backend-go/signatures/models.go | Corrects acknowledgment comment spelling. |
| cla-backend-go/signatures/email.go | Adds acknowledgment-invalidation notification. |
| cla-backend-go/signatures/dbmodels.go | Identifies approval-removal invalidation evidence. |
| cla-backend-go/signatures/approval_table_test.go | Tests approval-entry timestamps and updates. |
| cla-backend-go/projects_cla_groups/repository.go | Returns the foundation lookup error. |
| cla-backend-go/orgimport/state.go | Adds durable migration progress journal. |
| cla-backend-go/orgimport/recheck.go | Rechecks migrated groups for remaining events. |
| cla-backend-go/orgimport/mapping.go | Parses and validates migration mappings. |
| cla-backend-go/orgimport/awsreport.go | Adds CloudWatch logging and SES reporting. |
| cla-backend-go/orgimport/apex.go | Adds Salesforce find-or-create client. |
| cla-backend-go/orgimport/adapters.go | Adapts organization services and acknowledgment counts. |
| cla-backend-go/Makefile | Adds import builds and configurable lint flags. |
| cla-backend-go/go.mod | Updates primary backend dependencies. |
| cla-backend-go/github/github_org.go | Retrieves every organization-member page. |
| cla-backend-go/github/github_org_test.go | Tests member pagination and failures. |
| cla-backend-go/events/event_data_test.go | Tests project identifiers in event text. |
| cla-backend-go/emails/contact_cla_manager_templates.go | Standardizes acknowledgment wording. |
| cla-backend-go/config/ssm.go | Loads optional member-service settings. |
| cla-backend-go/config/config.go | Defines member-service configuration. |
| cla-backend-go/company/repository.go | Extends company persistence interface. |
| cla-backend-go/company/models.go | Adds migration metadata and deterministic parent selection. |
| cla-backend-go/company/mocks/mock_service.go | Updates generated company-service mock. |
| cla-backend-go/company/handlers.go | Resolves external IDs without requiring persisted rows. |
| cla-backend-go/cmd/server.go | Wires expanded services and caller verification. |
| cla-backend-go/cmd/org_import/main_test.go | Tests import CLI and journal capture. |
| cla-backend-go/cla_manager/service.go | Supplies CLA-group names for manager operations. |
| cla-backend-go/auth/trusted_caller.go | Requires expected audience for trusted callers. |
| .gitignore | Excludes local review and migration artifacts. |
| .github/copilot-instructions.md | Documents lint constraints and review scope. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…r the tuple Phase 0: 403 and dry-run follow-ups done in #5239; prod deploy goes through the release PR #5240 (dev -> main, 2026-10-07); the prod tuple needs cluster access, so the request goes to Jordan Evans. Phase 1: 2026-10-06 re-run counts and the new audit.csv columns; what the tool matches today vs. what it does not. Prod order-of-operations diagram in §3. Copilot's overview items: §2 counts reconciled against the live audit, step 10 lists the real state-file fields, `leave` marked as an exception to the §0 goal, 15/18-char handling stated as the tool does it, Phase 1 item 2 no longer claims enrichment the tool does not do. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Michal Lehotsky <mlehotsky@linuxfoundation.org>
mlehotskylf
left a comment
There was a problem hiding this comment.
Approved. The head tree is identical to dev, every code PR in it carries a human approval, the only new SSM keys (member-service URL/audience, report recipients) are already applied in prod, and the scheduled sweep stays off until ORG_IMPORT_SWEEP_PROD is set.
Two Copilot points worth a follow-up PR, not blockers: a parent CCLA request reusing a subsidiary row in EnsureCompanyForExternalID when no parent row exists, and the legacy backend comparing date_created as strings.
|
Merged @mlehotskylf - I'll make an EasyCLA release tomorrow after validating everything on my end. cc @ahmedomosanya |

M3milestone +orgs-importtool -prod.cc @mlehotskylf @ahmedomosanya
Signed-off-by: Łukasz Gryglicki lgryglicki@cncf.io
Assisted by OpenAI
Assisted by GitHub Copilot
Assisted by Claude