Files
Trevin Chow 9d70aee49b chore(ci): add CODEOWNERS for workflows and CODEOWNERS itself (#1472)
* chore(ci): add CODEOWNERS to gate edits to workflows and CODEOWNERS itself

Defense in depth alongside the org-level "Approve fork PR workflows for
first-time contributors who are new to GitHub" setting. Workflow files
have access to repo secrets at runtime; CODEOWNERS controls who can edit
the gating rules themselves. Both must require an explicit maintainer
review before merging.

Lists @tmchow and @mvanhorn so bus factor is 2 and a single absence
doesn't block workflow changes.

* chore(ci): extend CODEOWNERS to scripts/ and .github/scripts/

Greptile P1 flagged the gap: workflows run `bash .github/scripts/validate-skill-docs.sh`
and `scripts/golden.sh verify` in steps that have secrets in scope, so an
edit to either script directory has the same exfiltration potential as
editing the workflow YAML. Add both to the gate.
2026-05-15 11:33:54 -07:00

768 B