From 9d70aee49b88615917104386fcd4dba07daaaf94 Mon Sep 17 00:00:00 2001 From: Trevin Chow Date: Fri, 15 May 2026 11:33:54 -0700 Subject: [PATCH] chore(ci): add CODEOWNERS for workflows and CODEOWNERS itself (#1472) * chore(ci): add CODEOWNERS to gate edits to workflows and CODEOWNERS itself Defense in depth alongside the org-level "Approve fork PR workflows for first-time contributors who are new to GitHub" setting. Workflow files have access to repo secrets at runtime; CODEOWNERS controls who can edit the gating rules themselves. Both must require an explicit maintainer review before merging. Lists @tmchow and @mvanhorn so bus factor is 2 and a single absence doesn't block workflow changes. * chore(ci): extend CODEOWNERS to scripts/ and .github/scripts/ Greptile P1 flagged the gap: workflows run `bash .github/scripts/validate-skill-docs.sh` and `scripts/golden.sh verify` in steps that have secrets in scope, so an edit to either script directory has the same exfiltration potential as editing the workflow YAML. Add both to the gate. --- .github/CODEOWNERS | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 .github/CODEOWNERS diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 000000000..e0025c413 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,14 @@ +# Code owners for security-sensitive paths. +# A malicious PR that modifies these paths could exfiltrate secrets at workflow +# runtime or weaken the merge-gate; require an explicit maintainer review. +# See: docs.github.com/en/repositories/managing-your-repositorys-settings-and-security/customizing-your-repository/about-code-owners +# +# Coverage rationale: anything a workflow can `run:` is effectively part of +# the workflow's trust boundary. That includes workflow YAML, scripts checked +# into the repo that workflows invoke, and CODEOWNERS itself (so a malicious +# PR cannot strip the gate before exploiting it). + +.github/workflows/ @tmchow @mvanhorn +.github/scripts/ @tmchow @mvanhorn +scripts/ @tmchow @mvanhorn +.github/CODEOWNERS @tmchow @mvanhorn