-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCODEOWNERS
More file actions
62 lines (57 loc) · 2.92 KB
/
Copy pathCODEOWNERS
File metadata and controls
62 lines (57 loc) · 2.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
# CODEOWNERS (v0.10.6 plan 137)
#
# Routes review requests to specific owners when a PR touches a
# matching path. Combined with the branch-protection rule applied
# via `gh api PUT .../branches/main/protection` (see plans/137), the
# `require_code_owner_reviews: true` setting causes GitHub to block
# the merge button on any PR touching the listed paths until the
# owner grants a review.
#
# This file is the repo-side half of the Change A1 layer; the
# branch-protection rule is the GitHub-side half. Both must be in
# place for the founding `.github/**` gate. (just one without the
# other leaves a gap dependabot can exploit.)
#
# Owner handle is `@Roddygithub`; replace with the actual team
# handle for production deployments.
# v0.10.6 plan 137: any change to .github/** requires review
# by the repo's admin team. Prevents a patched workflow from
# landing without human eyes.
# Covers workflows, dependabot config, this file itself, and any
# future `.github/scripts/*` or `.github/actions/*` repos.
.github/** @Roddygithub
# Belt-and-braces: pin ALL ws-cascade libs to maintainer review.
# Each of these ships its own changes that ripple into apps/api:
# - gw2_core: events, models (lowest layer)
# - gw2_analytics: per-target aggregators, role detection
# - gw2_evtc_parser: arcdps evtc log parsing
# - gw2_api_client: GW2 community API client (auth, worlds)
# A regression in any one cascades as a P0 outage in apps/api.
# The 1-review-per-lib rule adds a human checkpoint before the
# cascade ships, complementing the per-PR CI gates.
/libs/gw2_core/** @Roddygithub
/libs/gw2_analytics/** @Roddygithub
/libs/gw2_evtc_parser/** @Roddygithub
/libs/gw2_api_client/** @Roddygithub
# v0.10.7 plan 139: high-risk non-lib paths. Round-2 reviewer
# flagged these as P0 data risk / infra breakages:
# - apps/api/alembic/versions/**: schema migrations. A bad
# migration = P0 data corruption/loss or full-table lock.
# The rule is NARROW (only migration files, not the rest of
# apps/api) so it doesn't bottleneck normal feature PRs.
# - docker-compose.yml: infra port + service config. A bad
# port can break the dev stack for the entire team. Reviewed
# by the owner so the same person who set up the port in
# plans/136-138 also gates future port changes.
# - Makefile: CI bootstrap targets. A bad target = CI broken
# for everyone until reverted.
# All 3 are gated because they touch blast-radius surfaces
# wider than a single PR can roll back quickly.
/apps/api/alembic/versions/** @Roddygithub
/docker-compose.yml @Roddygithub
/Makefile @Roddygithub
# Apps/api surface (routes, schemas, scripts): NOT gated. The
# apps/api IS the surface area for normal feature PRs; gating
# every API change on a maintainer review would bottleneck the
# team. The per-PR CI gates (ruff + mypy + pytest) handle that.
# Migrations and infra are gated above; feature code is not.