Skip to content

[M0] Add CODEOWNERS for security-sensitive paths #32

Description

@arthurpanhku

Goal

Require accountable review for security-sensitive repository paths.

Scope

  • Add .github/CODEOWNERS.
  • Cover workflows, app/core/, app/agent_gateway/, migrations, deployment files, and policy packs.
  • Keep ownership entries narrow enough to avoid unrelated review bottlenecks.

Acceptance criteria

  • Every sensitive path listed in the README M0 roadmap has an explicit owner.
  • The configured owner is valid and can approve pull requests.
  • A test pull request changing a sensitive path requests CODEOWNERS review.
  • Repository documentation explains how ownership changes are reviewed.

Dependencies

The main-branch ruleset issue will make CODEOWNERS approval mandatory.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationenhancementNew feature or requestmaintainer-ledSecurity-critical or architecture-heavy work led by maintainerspriority: p0Critical path for the next milestone

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions