Skip to content

chore: sync bounty board data - #219

Open
sl33ty wants to merge 1 commit into
stagingfrom
sl33ty/bounty-sync-signed
Open

sl33ty wants to merge 1 commit into
stagingfrom
sl33ty/bounty-sync-signed

Conversation

@sl33ty

@sl33ty sl33ty commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Publishes the four bounties to the board. Identical content to #218, recommitted so it can actually merge.

Why this exists rather than #218

sync-bounties.yml commits as github-actions[bot], using github.token because secrets.BOUNTY_SYNC_TOKEN is not set on this repo. That author fails both gates on the base branch:

  • verification/cla-signed fails, since the bot has never signed the CLA.
  • Merging is blocked by the verified-signature requirement, and the bot's commit is unsigned.

So the workflow runs green, produces a correct diff, and opens a PR that can never be merged. This is the same class of problem as the missing issues: read permission fixed in #208: the job succeeds while the outcome does not.

This commit carries the same generated file, authored by a CLA-covered maintainer and GPG-signed, so both gates pass.

Contents

Four bounty-labelled issues, regenerated into src/data/bounties.generated.json:

Bucket Bounty Reward
growth Walk into Arrow from every direction (#214) 1,920 ARROW
operations Put live Discord events on the community calls page (#215) 1,600 ARROW
operations AIP-009 Accelerator (#216) 1,440 ARROW
design Design the purchase flow on top of the store prototype (#217) 2,250 ARROW

Follow-up

The workflow still needs fixing so this is not manual every time. Add a BOUNTY_SYNC_TOKEN secret owned by a CLA-signed maintainer and have the commit step use it, rather than falling back to github.token. Tracked separately; this PR only unblocks the board.

Regenerated from the four bounty-labelled issues (#214, #215, #216, #217).
Identical content to the bot's run; recommitted under a signed, CLA-covered
author because the workflow commits as github-actions[bot], which can satisfy
neither the CLA check nor the verified-signature rule.
@sl33ty
sl33ty requested a review from a team as a code owner August 2, 2026 23:50
@cla-bot cla-bot Bot added the cla-signed label Aug 2, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant