mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 01:29:56 +00:00
chore: remove secops CODEOWNERS review routing (#151624)
## What Problem This Solves
Remove the blanket CODEOWNERS review routing to openclaw-secops, as requested by steipete and relayed by the author.
## User Impact
Security-related paths no longer automatically request secops code-owner review. Dependency Guard and Security Sensitive Guard remain unchanged, including dependency detection, lockfile autoscrub, comments/labels, and their SHA-bound approval commands. This does not remove dependency checks or change guard authorization.
## Why This Change Was Made
Remove only the secops CODEOWNERS block, the matching contribution restriction and stale lockfile-owner documentation, and two tests that require the retired CODEOWNERS entries. Keep steipete's ownership of CODEOWNERS and release-manager routing. Security scanning, dependency audits, and release approvals are untouched.
The earlier revision removed the guards too broadly; this revision restores them completely.
## Evidence
- All four guard suites pass: 59 tests.
- Both workflows, all three guard scripts, test routing, and guard script tests match the original baseline byte-for-byte.
- Two obsolete CODEOWNERS assertions removed; all guard behavior coverage retained.
- Targeted formatting, lint, and `git diff --check` pass.
- [Hosted CI](https://github.com/openclaw/openclaw/actions/runs/35324860885) failed in Telegram QA tooling: TS2353 at `scripts/mantis/run-request-telegram.mts:446` and four recorder tests whose fixture rejects `reply_to`. The failing caller, lease helper, recorder, fixture, and test are byte-identical between the actual CI merge `e1f02ecfae2b450fb4363c5205abd97c979c5aaa` and its main parent `c616fb4852`. The required CI check remains red; no bypass or merge attempted.
## Compatibility
No runtime, configuration, SDK, GitHub ruleset, or environment changes. Both `/allow-*` guard commands retain their existing behavior.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
This commit is contained in:
parent
2559dd3280
commit
36a6a6f565
5 changed files with 2 additions and 102 deletions
66
.github/CODEOWNERS
vendored
66
.github/CODEOWNERS
vendored
|
|
@ -1,73 +1,9 @@
|
|||
# Protect the ownership rules themselves.
|
||||
/.github/CODEOWNERS @steipete
|
||||
|
||||
# WARNING: GitHub CODEOWNERS uses last-match-wins semantics.
|
||||
# If you add overlapping rules below the secops block, include @openclaw/openclaw-secops
|
||||
# on those entries too or you can silently remove secops review routing.
|
||||
# Security-sensitive code, config, and docs require secops owner involvement
|
||||
# under repository policy. Live branch/ruleset settings decide merge enforcement.
|
||||
/SECURITY.md @openclaw/openclaw-secops
|
||||
/.github/dependabot.yml @openclaw/openclaw-secops
|
||||
/.github/codeql/ @openclaw/openclaw-secops
|
||||
/.github/workflows/codeql.yml @openclaw/openclaw-secops
|
||||
/.github/workflows/codeql-android-critical-security.yml @openclaw/openclaw-secops
|
||||
/.github/workflows/codeql-critical-quality.yml @openclaw/openclaw-secops
|
||||
/.github/workflows/dependency-guard.yml @openclaw/openclaw-secops
|
||||
/.github/workflows/security-sensitive-guard.yml @openclaw/openclaw-secops
|
||||
/test/scripts/dependency-guard-workflow.test.ts @openclaw/openclaw-secops
|
||||
/test/scripts/dependency-guard-script.test.ts @openclaw/openclaw-secops
|
||||
/test/scripts/security-sensitive-guard-workflow.test.ts @openclaw/openclaw-secops
|
||||
/test/scripts/security-sensitive-guard-script.test.ts @openclaw/openclaw-secops
|
||||
/scripts/github/dependency-guard.mjs @openclaw/openclaw-secops
|
||||
/scripts/github/guard-shared.mjs @openclaw/openclaw-secops
|
||||
/scripts/github/security-sensitive-guard.mjs @openclaw/openclaw-secops
|
||||
/.gitignore @openclaw/openclaw-secops
|
||||
/package-lock.json @openclaw/openclaw-secops
|
||||
/extensions/*/package-lock.json @openclaw/openclaw-secops
|
||||
/pnpm-lock.yaml @openclaw/openclaw-secops
|
||||
/scripts/generate-npm-package-lock.mjs @openclaw/openclaw-secops
|
||||
/src/security/ @openclaw/openclaw-secops
|
||||
/src/secrets/ @openclaw/openclaw-secops
|
||||
/src/config/*secret*.ts @openclaw/openclaw-secops
|
||||
/src/config/**/*secret*.ts @openclaw/openclaw-secops
|
||||
/src/gateway/*auth*.ts @openclaw/openclaw-secops
|
||||
/src/gateway/**/*auth*.ts @openclaw/openclaw-secops
|
||||
/src/gateway/*secret*.ts @openclaw/openclaw-secops
|
||||
/src/gateway/**/*secret*.ts @openclaw/openclaw-secops
|
||||
/src/gateway/security-path*.ts @openclaw/openclaw-secops
|
||||
/src/gateway/resolve-configured-secret-input-string*.ts @openclaw/openclaw-secops
|
||||
/packages/gateway-protocol/src/**/*secret*.ts @openclaw/openclaw-secops
|
||||
/src/gateway/server-methods/secrets*.ts @openclaw/openclaw-secops
|
||||
/src/agents/*auth*.ts @openclaw/openclaw-secops
|
||||
/src/agents/**/*auth*.ts @openclaw/openclaw-secops
|
||||
/src/agents/auth-profiles*.ts @openclaw/openclaw-secops
|
||||
/src/agents/auth-health*.ts @openclaw/openclaw-secops
|
||||
/src/agents/auth-profiles/ @openclaw/openclaw-secops
|
||||
/src/agents/sandbox.ts @openclaw/openclaw-secops
|
||||
/src/agents/sandbox-*.ts @openclaw/openclaw-secops
|
||||
/src/agents/sandbox/ @openclaw/openclaw-secops
|
||||
/src/infra/secret-file*.ts @openclaw/openclaw-secops
|
||||
/src/cron/stagger.ts @openclaw/openclaw-secops
|
||||
/src/cron/service/jobs.ts @openclaw/openclaw-secops
|
||||
/docs/security/ @openclaw/openclaw-secops
|
||||
/docs/gateway/authentication.md @openclaw/openclaw-secops
|
||||
/docs/gateway/sandbox-vs-tool-policy-vs-elevated.md @openclaw/openclaw-secops
|
||||
/docs/gateway/sandboxing.md @openclaw/openclaw-secops
|
||||
/docs/gateway/sandboxing/ @openclaw/openclaw-secops
|
||||
/docs/gateway/secrets-plan-contract.md @openclaw/openclaw-secops
|
||||
/docs/gateway/secrets.md @openclaw/openclaw-secops
|
||||
/docs/gateway/secrets/ @openclaw/openclaw-secops
|
||||
/docs/gateway/security/ @openclaw/openclaw-secops
|
||||
/docs/cli/approvals.md @openclaw/openclaw-secops
|
||||
/docs/cli/sandbox.md @openclaw/openclaw-secops
|
||||
/docs/cli/security.md @openclaw/openclaw-secops
|
||||
/docs/cli/secrets.md @openclaw/openclaw-secops
|
||||
/docs/reference/secretref-credential-surface.md @openclaw/openclaw-secops
|
||||
/docs/reference/secretref-user-supplied-credentials-matrix.json @openclaw/openclaw-secops
|
||||
|
||||
# Release workflow and its supporting release-path checks.
|
||||
/.github/workflows/openclaw-npm-release.yml @openclaw/openclaw-release-managers
|
||||
/docs/reference/RELEASING.md @openclaw/openclaw-release-managers
|
||||
/scripts/openclaw-npm-publish.sh @openclaw/openclaw-release-managers
|
||||
/scripts/openclaw-npm-release-check.ts @openclaw/openclaw-release-managers
|
||||
/scripts/release-check.ts @openclaw/openclaw-release-managers
|
||||
/scripts/release-check.ts @openclaw/openclaw-release-managers
|
||||
|
|
@ -104,7 +104,6 @@ must declare their own development dependencies rather than rely on hoisting.
|
|||
- Describe what & why
|
||||
- **Include screenshots** — one showing the problem/before, one showing the fix/after (for UI or visual changes)
|
||||
- Use American English spelling and grammar in code, comments, docs, and UI strings
|
||||
- Do not edit files covered by `CODEOWNERS` security ownership unless a listed owner authored or explicitly requested the change, or is already reviewing it with you. For governance changes to ownership/review policy itself, explicit direction from an organization owner is also sufficient only when live GitHub organization membership shows `state: active` and `role: admin`; repository `ADMIN`, `viewerCanAdminister`, or bypass permission alone never qualifies. Neither route waives a GitHub-enforced approval rule. Treat those paths as restricted review surfaces, not opportunistic cleanup targets.
|
||||
|
||||
## Local commit hook
|
||||
|
||||
|
|
|
|||
|
|
@ -221,8 +221,7 @@ npm check covers npm bulk advisories only, not every upstream advisory source.
|
|||
The triage owner is **@steipete**, set on 2026-09-03 in
|
||||
[#137960](https://github.com/openclaw/openclaw/pull/137960). No `.github/CODEOWNERS`
|
||||
rule covers `.github/workflows/dependency-audit.yml`, so this line is the only
|
||||
record of that ownership. Review routing for a fix follows the lockfile owner
|
||||
`@openclaw/openclaw-secops`, which owns `/pnpm-lock.yaml` and `/package-lock.json`.
|
||||
record of that ownership.
|
||||
Investigate failed scheduled runs and rerun the strict workflow to confirm
|
||||
recovery:
|
||||
|
||||
|
|
|
|||
|
|
@ -5,7 +5,6 @@ import { describe, expect, it } from "vitest";
|
|||
import { parse } from "yaml";
|
||||
|
||||
const WORKFLOW = ".github/workflows/dependency-guard.yml";
|
||||
const CODEOWNERS = ".github/CODEOWNERS";
|
||||
|
||||
type WorkflowStep = {
|
||||
"continue-on-error"?: boolean;
|
||||
|
|
@ -264,18 +263,4 @@ describe("dependency guard workflow", () => {
|
|||
expect(autoscrubCandidateIndex).toBeGreaterThan(trustedActorIndex);
|
||||
expect(autoscrubOutputIndex).toBeGreaterThan(trustedActorIndex);
|
||||
});
|
||||
|
||||
it("requires secops review for future workflow or guard changes", () => {
|
||||
const codeowners = readFileSync(CODEOWNERS, "utf8");
|
||||
expect(codeowners).toContain(
|
||||
"/.github/workflows/dependency-guard.yml @openclaw/openclaw-secops",
|
||||
);
|
||||
expect(codeowners).toContain(
|
||||
"/test/scripts/dependency-guard-workflow.test.ts @openclaw/openclaw-secops",
|
||||
);
|
||||
expect(codeowners).toContain("/scripts/github/dependency-guard.mjs @openclaw/openclaw-secops");
|
||||
expect(codeowners).toContain("/package-lock.json @openclaw/openclaw-secops");
|
||||
expect(codeowners).toContain("/extensions/*/package-lock.json @openclaw/openclaw-secops");
|
||||
expect(codeowners).toContain("/pnpm-lock.yaml @openclaw/openclaw-secops");
|
||||
});
|
||||
});
|
||||
|
|
|
|||
|
|
@ -4,7 +4,6 @@ import { describe, expect, it } from "vitest";
|
|||
import { parse } from "yaml";
|
||||
|
||||
const WORKFLOW = ".github/workflows/security-sensitive-guard.yml";
|
||||
const CODEOWNERS = ".github/CODEOWNERS";
|
||||
|
||||
type WorkflowStep = {
|
||||
env?: Record<string, string>;
|
||||
|
|
@ -122,22 +121,4 @@ describe("security-sensitive guard workflow", () => {
|
|||
expect(script).toContain("A later push requires a fresh approval.");
|
||||
expect(script).toContain("process.exitCode = 1");
|
||||
});
|
||||
|
||||
it("requires secops review for future workflow or guard changes", () => {
|
||||
const codeowners = readFileSync(CODEOWNERS, "utf8");
|
||||
expect(codeowners).toContain(
|
||||
"/.github/workflows/security-sensitive-guard.yml @openclaw/openclaw-secops",
|
||||
);
|
||||
expect(codeowners).toContain(
|
||||
"/test/scripts/security-sensitive-guard-workflow.test.ts @openclaw/openclaw-secops",
|
||||
);
|
||||
expect(codeowners).toContain(
|
||||
"/test/scripts/security-sensitive-guard-script.test.ts @openclaw/openclaw-secops",
|
||||
);
|
||||
expect(codeowners).toContain(
|
||||
"/scripts/github/security-sensitive-guard.mjs @openclaw/openclaw-secops",
|
||||
);
|
||||
expect(codeowners).toContain("/scripts/github/guard-shared.mjs @openclaw/openclaw-secops");
|
||||
expect(codeowners).toContain("/.gitignore @openclaw/openclaw-secops");
|
||||
});
|
||||
});
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue