Skip to content

chore: require an engineering approval on every change - #4

Open
Alex (Alexkuva) wants to merge 1 commit into
mainfrom
chore/codeowners
Open

Alex (Alexkuva) wants to merge 1 commit into
mainfrom
chore/codeowners

Conversation

@Alexkuva

Copy link
Copy Markdown
Contributor

Adds .github/CODEOWNERS, which makes @kaitencloud/engineering the owner of every path.

The default-branch ruleset already requires a review from a code owner, but without this file
the rule applied to nothing: any approval from an account with write access counted. That
included GitHub Actions, which this repository allows to approve pull requests, and the apps
installed across the organization with write access to pull requests.

With it, every pull request needs the approval of a member of @kaitencloud/engineering. An app
or a workflow's token cannot belong to a team, and an author cannot approve their own pull
request, so the approval has to come from another engineer.

GitHub validates the file (GET /repos/{owner}/{repo}/codeowners/errors): no errors, the team
is known and has write access.

The rule applies from the pull request after this one: GitHub reads CODEOWNERS from the base
branch.

🤖 Generated with Claude Code · ✅ Tested and approved by Alex (@Alexkuva), maintainer

The default-branch ruleset already requires a review from a code owner,
but without a CODEOWNERS file that rule applied to nothing: any approval
from an account with write access counted. That included GitHub Actions,
which the repository allows to approve pull requests, and the apps
installed across the organization with write access to pull requests.

.github/CODEOWNERS makes @kaitencloud/engineering the owner of every
path, so a pull request now needs the approval of a member of that team.
An app or a workflow's token cannot belong to a team, and the author
cannot approve their own pull request, so the approval has to come from
another engineer.

Signed-off-by: Alexandre Bergere <[email protected]>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants