From 36a6a6f5650c783691eae9401aab9583a0266fcd Mon Sep 17 00:00:00 2001 From: Ayaan Zaidi Date: Fri, 18 Sep 2026 14:51:31 +0530 Subject: [PATCH] chore: remove secops CODEOWNERS review routing (#151624) ## What Problem This Solves Remove the blanket CODEOWNERS review routing to openclaw-secops, as requested by steipete and relayed by the author. ## User Impact Security-related paths no longer automatically request secops code-owner review. Dependency Guard and Security Sensitive Guard remain unchanged, including dependency detection, lockfile autoscrub, comments/labels, and their SHA-bound approval commands. This does not remove dependency checks or change guard authorization. ## Why This Change Was Made Remove only the secops CODEOWNERS block, the matching contribution restriction and stale lockfile-owner documentation, and two tests that require the retired CODEOWNERS entries. Keep steipete's ownership of CODEOWNERS and release-manager routing. Security scanning, dependency audits, and release approvals are untouched. The earlier revision removed the guards too broadly; this revision restores them completely. ## Evidence - All four guard suites pass: 59 tests. - Both workflows, all three guard scripts, test routing, and guard script tests match the original baseline byte-for-byte. - Two obsolete CODEOWNERS assertions removed; all guard behavior coverage retained. - Targeted formatting, lint, and `git diff --check` pass. - [Hosted CI](https://github.com/openclaw/openclaw/actions/runs/35324860885) failed in Telegram QA tooling: TS2353 at `scripts/mantis/run-request-telegram.mts:446` and four recorder tests whose fixture rejects `reply_to`. The failing caller, lease helper, recorder, fixture, and test are byte-identical between the actual CI merge `e1f02ecfae2b450fb4363c5205abd97c979c5aaa` and its main parent `c616fb4852ef9d6904427914bd75d2ba170b8146`. The required CI check remains red; no bypass or merge attempted. ## Compatibility No runtime, configuration, SDK, GitHub ruleset, or environment changes. Both `/allow-*` guard commands retain their existing behavior. Co-authored-by: Ayaan Zaidi --- .github/CODEOWNERS | 66 +------------------ CONTRIBUTING.md | 1 - docs/ci/scheduled-workflows.md | 3 +- .../scripts/dependency-guard-workflow.test.ts | 15 ----- .../security-sensitive-guard-workflow.test.ts | 19 ------ 5 files changed, 2 insertions(+), 102 deletions(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 1071f69ba079..01f7c10269cf 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1,73 +1,9 @@ # Protect the ownership rules themselves. /.github/CODEOWNERS @steipete -# WARNING: GitHub CODEOWNERS uses last-match-wins semantics. -# If you add overlapping rules below the secops block, include @openclaw/openclaw-secops -# on those entries too or you can silently remove secops review routing. -# Security-sensitive code, config, and docs require secops owner involvement -# under repository policy. Live branch/ruleset settings decide merge enforcement. -/SECURITY.md @openclaw/openclaw-secops -/.github/dependabot.yml @openclaw/openclaw-secops -/.github/codeql/ @openclaw/openclaw-secops -/.github/workflows/codeql.yml @openclaw/openclaw-secops -/.github/workflows/codeql-android-critical-security.yml @openclaw/openclaw-secops -/.github/workflows/codeql-critical-quality.yml @openclaw/openclaw-secops -/.github/workflows/dependency-guard.yml @openclaw/openclaw-secops -/.github/workflows/security-sensitive-guard.yml @openclaw/openclaw-secops -/test/scripts/dependency-guard-workflow.test.ts @openclaw/openclaw-secops -/test/scripts/dependency-guard-script.test.ts @openclaw/openclaw-secops -/test/scripts/security-sensitive-guard-workflow.test.ts @openclaw/openclaw-secops -/test/scripts/security-sensitive-guard-script.test.ts @openclaw/openclaw-secops -/scripts/github/dependency-guard.mjs @openclaw/openclaw-secops -/scripts/github/guard-shared.mjs @openclaw/openclaw-secops -/scripts/github/security-sensitive-guard.mjs @openclaw/openclaw-secops -/.gitignore @openclaw/openclaw-secops -/package-lock.json @openclaw/openclaw-secops -/extensions/*/package-lock.json @openclaw/openclaw-secops -/pnpm-lock.yaml @openclaw/openclaw-secops -/scripts/generate-npm-package-lock.mjs @openclaw/openclaw-secops -/src/security/ @openclaw/openclaw-secops -/src/secrets/ @openclaw/openclaw-secops -/src/config/*secret*.ts @openclaw/openclaw-secops -/src/config/**/*secret*.ts @openclaw/openclaw-secops -/src/gateway/*auth*.ts @openclaw/openclaw-secops -/src/gateway/**/*auth*.ts @openclaw/openclaw-secops -/src/gateway/*secret*.ts @openclaw/openclaw-secops -/src/gateway/**/*secret*.ts @openclaw/openclaw-secops -/src/gateway/security-path*.ts @openclaw/openclaw-secops -/src/gateway/resolve-configured-secret-input-string*.ts @openclaw/openclaw-secops -/packages/gateway-protocol/src/**/*secret*.ts @openclaw/openclaw-secops -/src/gateway/server-methods/secrets*.ts @openclaw/openclaw-secops -/src/agents/*auth*.ts @openclaw/openclaw-secops -/src/agents/**/*auth*.ts @openclaw/openclaw-secops -/src/agents/auth-profiles*.ts @openclaw/openclaw-secops -/src/agents/auth-health*.ts @openclaw/openclaw-secops -/src/agents/auth-profiles/ @openclaw/openclaw-secops -/src/agents/sandbox.ts @openclaw/openclaw-secops -/src/agents/sandbox-*.ts @openclaw/openclaw-secops -/src/agents/sandbox/ @openclaw/openclaw-secops -/src/infra/secret-file*.ts @openclaw/openclaw-secops -/src/cron/stagger.ts @openclaw/openclaw-secops -/src/cron/service/jobs.ts @openclaw/openclaw-secops -/docs/security/ @openclaw/openclaw-secops -/docs/gateway/authentication.md @openclaw/openclaw-secops -/docs/gateway/sandbox-vs-tool-policy-vs-elevated.md @openclaw/openclaw-secops -/docs/gateway/sandboxing.md @openclaw/openclaw-secops -/docs/gateway/sandboxing/ @openclaw/openclaw-secops -/docs/gateway/secrets-plan-contract.md @openclaw/openclaw-secops -/docs/gateway/secrets.md @openclaw/openclaw-secops -/docs/gateway/secrets/ @openclaw/openclaw-secops -/docs/gateway/security/ @openclaw/openclaw-secops -/docs/cli/approvals.md @openclaw/openclaw-secops -/docs/cli/sandbox.md @openclaw/openclaw-secops -/docs/cli/security.md @openclaw/openclaw-secops -/docs/cli/secrets.md @openclaw/openclaw-secops -/docs/reference/secretref-credential-surface.md @openclaw/openclaw-secops -/docs/reference/secretref-user-supplied-credentials-matrix.json @openclaw/openclaw-secops - # Release workflow and its supporting release-path checks. /.github/workflows/openclaw-npm-release.yml @openclaw/openclaw-release-managers /docs/reference/RELEASING.md @openclaw/openclaw-release-managers /scripts/openclaw-npm-publish.sh @openclaw/openclaw-release-managers /scripts/openclaw-npm-release-check.ts @openclaw/openclaw-release-managers -/scripts/release-check.ts @openclaw/openclaw-release-managers +/scripts/release-check.ts @openclaw/openclaw-release-managers \ No newline at end of file diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 7af867e21ded..d0e2d79b0c48 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -104,7 +104,6 @@ must declare their own development dependencies rather than rely on hoisting. - Describe what & why - **Include screenshots** — one showing the problem/before, one showing the fix/after (for UI or visual changes) - Use American English spelling and grammar in code, comments, docs, and UI strings -- Do not edit files covered by `CODEOWNERS` security ownership unless a listed owner authored or explicitly requested the change, or is already reviewing it with you. For governance changes to ownership/review policy itself, explicit direction from an organization owner is also sufficient only when live GitHub organization membership shows `state: active` and `role: admin`; repository `ADMIN`, `viewerCanAdminister`, or bypass permission alone never qualifies. Neither route waives a GitHub-enforced approval rule. Treat those paths as restricted review surfaces, not opportunistic cleanup targets. ## Local commit hook diff --git a/docs/ci/scheduled-workflows.md b/docs/ci/scheduled-workflows.md index 42f6a763a0a5..442ab024e680 100644 --- a/docs/ci/scheduled-workflows.md +++ b/docs/ci/scheduled-workflows.md @@ -221,8 +221,7 @@ npm check covers npm bulk advisories only, not every upstream advisory source. The triage owner is **@steipete**, set on 2026-09-03 in [#137960](https://github.com/openclaw/openclaw/pull/137960). No `.github/CODEOWNERS` rule covers `.github/workflows/dependency-audit.yml`, so this line is the only -record of that ownership. Review routing for a fix follows the lockfile owner -`@openclaw/openclaw-secops`, which owns `/pnpm-lock.yaml` and `/package-lock.json`. +record of that ownership. Investigate failed scheduled runs and rerun the strict workflow to confirm recovery: diff --git a/test/scripts/dependency-guard-workflow.test.ts b/test/scripts/dependency-guard-workflow.test.ts index d4afe0e3add1..edb83e7aafcf 100644 --- a/test/scripts/dependency-guard-workflow.test.ts +++ b/test/scripts/dependency-guard-workflow.test.ts @@ -5,7 +5,6 @@ import { describe, expect, it } from "vitest"; import { parse } from "yaml"; const WORKFLOW = ".github/workflows/dependency-guard.yml"; -const CODEOWNERS = ".github/CODEOWNERS"; type WorkflowStep = { "continue-on-error"?: boolean; @@ -264,18 +263,4 @@ describe("dependency guard workflow", () => { expect(autoscrubCandidateIndex).toBeGreaterThan(trustedActorIndex); expect(autoscrubOutputIndex).toBeGreaterThan(trustedActorIndex); }); - - it("requires secops review for future workflow or guard changes", () => { - const codeowners = readFileSync(CODEOWNERS, "utf8"); - expect(codeowners).toContain( - "/.github/workflows/dependency-guard.yml @openclaw/openclaw-secops", - ); - expect(codeowners).toContain( - "/test/scripts/dependency-guard-workflow.test.ts @openclaw/openclaw-secops", - ); - expect(codeowners).toContain("/scripts/github/dependency-guard.mjs @openclaw/openclaw-secops"); - expect(codeowners).toContain("/package-lock.json @openclaw/openclaw-secops"); - expect(codeowners).toContain("/extensions/*/package-lock.json @openclaw/openclaw-secops"); - expect(codeowners).toContain("/pnpm-lock.yaml @openclaw/openclaw-secops"); - }); }); diff --git a/test/scripts/security-sensitive-guard-workflow.test.ts b/test/scripts/security-sensitive-guard-workflow.test.ts index b5887a614e34..0aaa183dc092 100644 --- a/test/scripts/security-sensitive-guard-workflow.test.ts +++ b/test/scripts/security-sensitive-guard-workflow.test.ts @@ -4,7 +4,6 @@ import { describe, expect, it } from "vitest"; import { parse } from "yaml"; const WORKFLOW = ".github/workflows/security-sensitive-guard.yml"; -const CODEOWNERS = ".github/CODEOWNERS"; type WorkflowStep = { env?: Record; @@ -122,22 +121,4 @@ describe("security-sensitive guard workflow", () => { expect(script).toContain("A later push requires a fresh approval."); expect(script).toContain("process.exitCode = 1"); }); - - it("requires secops review for future workflow or guard changes", () => { - const codeowners = readFileSync(CODEOWNERS, "utf8"); - expect(codeowners).toContain( - "/.github/workflows/security-sensitive-guard.yml @openclaw/openclaw-secops", - ); - expect(codeowners).toContain( - "/test/scripts/security-sensitive-guard-workflow.test.ts @openclaw/openclaw-secops", - ); - expect(codeowners).toContain( - "/test/scripts/security-sensitive-guard-script.test.ts @openclaw/openclaw-secops", - ); - expect(codeowners).toContain( - "/scripts/github/security-sensitive-guard.mjs @openclaw/openclaw-secops", - ); - expect(codeowners).toContain("/scripts/github/guard-shared.mjs @openclaw/openclaw-secops"); - expect(codeowners).toContain("/.gitignore @openclaw/openclaw-secops"); - }); });