Skip to content

Commit 01744c8

Browse files
committed
Require a maintainer's approval to merge
The repository inherits a collaborator list from the organisation, so about a dozen people can push and, with no review required, merge their own work. That is the wrong default for a public repository. Name the owners explicitly so the protection rule on main has somebody to demand an approval from.
1 parent f4d7443 commit 01744c8

1 file changed

Lines changed: 12 additions & 0 deletions

File tree

‎.github/CODEOWNERS‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
# Who has to approve a change before it can reach main.
2+
#
3+
# This repository is public, and its collaborator list is inherited from the
4+
# organisation, so a great many people can open and push branches. Merging is
5+
# deliberately narrower: the branch protection rule on `main` requires an
6+
# approving review from an owner listed here, and it applies to administrators
7+
# too, so there is no path that lands a change without one.
8+
#
9+
# Widening this list widens who can approve. Add people who know the codebase
10+
# well enough to say no.
11+
12+
* @davidmckayv @guidovizoso

0 commit comments

Comments
 (0)