Skip to content

docs: record why this repo stays public and add codeowners - #33

Merged
CameronBrooks11 merged 1 commit into
mainfrom
docs/public-and-codeowners
Sep 28, 2026
Merged

CameronBrooks11 merged 1 commit into
mainfrom
docs/public-and-codeowners

Conversation

@CameronBrooks11

Copy link
Copy Markdown
Contributor

Summary

This PR does two things:

  • README: records why this repository must stay public, in three reasons. It also records that .gitleaks.toml takes effect across the org the moment it merges, that the fetch of it is deliberately fail-closed and what that costs, and that a repo-local .gitleaks.toml must extend the org one.
  • .github/CODEOWNERS: adds an owner for /.gitleaks.toml and /.github/workflows/.

.gitleaks.toml itself is unchanged.

Proof

$ curl -s -o /dev/null -w "%{http_code}\n" https://raw.githubusercontent.com/FlowMatrix-AI/.github/main/.gitleaks.toml
200

The fetch this README describes is at .github/workflows/gitleaks.yml ("Fetch the org allowlist": curl -fsSL .../main/.gitleaks.toml, with no fallback).

Not in this PR

CODEOWNERS only routes review requests. Making code-owner review required on main is a ruleset change. It needs a bypass decision, because every human in the org is an org owner, so it is left for that decision.

@CameronBrooks11
CameronBrooks11 merged commit a53251c into main Sep 28, 2026
2 checks passed
@CameronBrooks11
CameronBrooks11 deleted the docs/public-and-codeowners branch September 28, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant