From 439e93dc6b157b3729fe918a0e3cbfeb0b6685a2 Mon Sep 17 00:00:00 2001 From: Alexandre Bergere Date: Thu, 1 Oct 2026 00:19:56 +0200 Subject: [PATCH] chore: require an engineering approval on every change The default-branch ruleset already requires a review from a code owner, but without a CODEOWNERS file that rule applied to nothing: any approval from an account with write access counted. That included GitHub Actions, which the repository allows to approve pull requests, and the apps installed across the organization with write access to pull requests. .github/CODEOWNERS makes @kaitencloud/engineering the owner of every path, so a pull request now needs the approval of a member of that team. An app or a workflow's token cannot belong to a team, and the author cannot approve their own pull request, so the approval has to come from another engineer. Signed-off-by: Alexandre Bergere --- .github/CODEOWNERS | 6 ++++++ 1 file changed, 6 insertions(+) create mode 100644 .github/CODEOWNERS diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..da45ec0 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,6 @@ +# Every change to this repository needs the approval of a member of @kaitencloud/engineering. +# +# The default-branch ruleset requires a review from a code owner. With this file, that means an +# approval from one of the team's members -- never from a GitHub App or a workflow's token, +# which cannot belong to a team, and never from the pull request's own author. +* @kaitencloud/engineering