Please note our CLA explicitly include a clause to require Core Devices to distribute all contributions under an OSI-compatible FOSS license (e.g. GPLv3). So no contributions can be 'stolen'.
https://ericmigi.notion.site/Core-Devices-Software-Licensing...
I'm the first to agree that contributions can't be stolen in this scenario but read the threads I'm referring to. People feel that way anyway if you stop supporting a component or distribute your focus between a free and a paid tier.
What we need is more awareness that looking at the license alone is not enough to make an informed decision if contributing to a project is aligned with the contributors attitude and personal goals.
With that in mind: Thank you for putting the CLA right in the repo where it belongs and people can easily find it. Many organizations put a license upfront and bury the CLA. For a particularly bad example try MonoDB.
But OSI-compatible FOSS licenses include pushover ones like MIT, so even though you couldn't steal all of the contributions to make a proprietary fork, any other company then could.