-
Notifications
You must be signed in to change notification settings - Fork 5
Expand file tree
/
Copy pathCODEOWNERS
More file actions
Validating CODEOWNERS rules...
32 lines (31 loc) · 1.56 KB
/
Copy pathCODEOWNERS
File metadata and controls
32 lines (31 loc) · 1.56 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
# CODEOWNERS — paths that require @wnstfy approval before merge.
#
# Branch protection has `require_code_owner_reviews: true`, so any PR
# touching these paths is blocked until @wnstfy approves. Listing only
# plumbing paths here (not routine compose / docs / template files) is
# deliberate: it preserves Renovate auto-merge for routine image bumps
# while gating high-risk changes that affect the security, CI, or
# release pipeline.
#
# Why each line is here:
# - .github/workflows/ CI/CD entry points; a compromised workflow runs
# with repo secrets and write access.
# - .github/scripts/ Helper scripts executed by workflows.
# - /scripts/ Repo-level scripts (e.g. no-latest pre-commit gate).
# - /SECURITY.md Security policy + reporting contact.
# - /.gitattributes Controls the release tarball; export-ignore on the
# wrong file silently hides it from Scorecard
# (see Scorecard tarball-scan behaviour).
# - /renovate.json Dependency-update policy, including auto-merge rules.
# - /.pre-commit-config.yaml + /.yamllint.yml Contributor-side enforcement.
# - /CODEOWNERS Prevent self-elevation: any change here also
# requires @wnstfy.
/.github/workflows/ @wnstfy
/.github/scripts/ @wnstfy
/scripts/ @wnstfy
/SECURITY.md @wnstfy
/.gitattributes @wnstfy
/renovate.json @wnstfy
/.pre-commit-config.yaml @wnstfy
/.yamllint.yml @wnstfy
/CODEOWNERS @wnstfy