feat(action): trust-check/codeowners - Verify actor in CODEOWNERS
- Dominant language
- Shell
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
## Parent Epic
Part of #22 (Atomic Release Pipeline Actions)
## Priority
P2 - Trust validation for auto-merge workflows
## Description
Create a composite action that verifies the workflow actor is listed in CODEOWNERS for relevant paths.
## Inputs
| Input | Required | Default | Description |
|-------|----------|---------|-------------|
| `actor` | No | `github.actor` | GitHub username to verify |
| `paths` | No | - | Paths to check ownership for (comma-separated) |
| `codeowners-path` | No | `.github/CODEOWNERS` | Path to CODEOWNERS file |
| `token` | No | `github.token` | GitHub token |
## Outputs
| Output | Description |
|--------|-------------|
| `is-owner` | "true" if actor is a codeowner |
| `matched-pattern` | CODEOWNERS pattern that matched |
| `owners` | Comma-separated list of owners for the path |
## Usage Example
```yaml
- uses: arustydev/gha/actions/trust-check/codeowners@v1
id: codeowners
with:
actor: ${{ github.actor }}
paths: "charts/my-chart"
- if: steps.codeowners.outputs.is-owner == 'true'
run: echo "Actor is authorized"
```
## Implementation Notes
- Parses CODEOWNERS file format
- Supports user, team, and email patterns
- Handles glob patterns in CODEOWNERS
- Checks team membership via API if team pattern
## Source Reference
`helm-charts/.github/workflows/auto-merge-integration.yaml`:
- CODEOWNERS verification logic
Contributor guide
Assessment
This issue has not been assessed yet.