aRustyDev / aRustyDev/gh

feat(action): trust-check/codeowners - Verify actor in CODEOWNERS

Aperta
#40 0 commenti 0 reazioni 1 assegnatario Rivendicata da @aRustyDev Vedi su GitHub
enhancement new-action
Lingua principale
Shell
Stelle
0
Fork
0
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

## Parent Epic
Part of #22 (Atomic Release Pipeline Actions)

## Priority
P2 - Trust validation for auto-merge workflows

## Description

Create a composite action that verifies the workflow actor is listed in CODEOWNERS for relevant paths.

## Inputs

| Input | Required | Default | Description |
|-------|----------|---------|-------------|
| `actor` | No | `github.actor` | GitHub username to verify |
| `paths` | No | - | Paths to check ownership for (comma-separated) |
| `codeowners-path` | No | `.github/CODEOWNERS` | Path to CODEOWNERS file |
| `token` | No | `github.token` | GitHub token |

## Outputs

| Output | Description |
|--------|-------------|
| `is-owner` | "true" if actor is a codeowner |
| `matched-pattern` | CODEOWNERS pattern that matched |
| `owners` | Comma-separated list of owners for the path |

## Usage Example

```yaml
- uses: arustydev/gha/actions/trust-check/codeowners@v1
id: codeowners
with:
actor: ${{ github.actor }}
paths: "charts/my-chart"

- if: steps.codeowners.outputs.is-owner == 'true'
run: echo "Actor is authorized"
```

## Implementation Notes

- Parses CODEOWNERS file format
- Supports user, team, and email patterns
- Handles glob patterns in CODEOWNERS
- Checks team membership via API if team pattern

## Source Reference

`helm-charts/.github/workflows/auto-merge-integration.yaml`:
- CODEOWNERS verification logic

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.