feat(action): trust-check/codeowners - Verify actor in CODEOWNERS
@aRustyDev is already working on this.
Since Jan 27, 2026.
Assessment
This issue has not been assessed yet.
Description
Parent Epic
Part of #22 (Atomic Release Pipeline Actions)
Priority
P2 - Trust validation for auto-merge workflows
Description
Create a composite action that verifies the workflow actor is listed in CODEOWNERS for relevant paths.
Inputs
| Input | Required | Default | Description |
|---|---|---|---|
actor |
No | github.actor |
GitHub username to verify |
paths |
No | - | Paths to check ownership for (comma-separated) |
codeowners-path |
No | .github/CODEOWNERS |
Path to CODEOWNERS file |
token |
No | github.token |
GitHub token |
Outputs
| Output | Description |
|---|---|
is-owner |
"true" if actor is a codeowner |
matched-pattern |
CODEOWNERS pattern that matched |
owners |
Comma-separated list of owners for the path |
Usage Example
- uses: arustydev/gha/actions/trust-check/codeowners@v1
id: codeowners
with:
actor: ${{ github.actor }}
paths: "charts/my-chart"
- if: steps.codeowners.outputs.is-owner == 'true'
run: echo "Actor is authorized"
Implementation Notes
- Parses CODEOWNERS file format
- Supports user, team, and email patterns
- Handles glob patterns in CODEOWNERS
- Checks team membership via API if team pattern
Source Reference
helm-charts/.github/workflows/auto-merge-integration.yaml:
- CODEOWNERS verification logic
- Dominant language
- Shell
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from aRustyDev/gh
-
dependencies github-actions
Difficulty 1/5 Under an hour Newbie friendliness 10/100
-
dependencies github-actions
Difficulty 1/5 Under an hour Newbie friendliness 15/100
-
dependencies github-actions
Difficulty 1/5 Under an hour Newbie friendliness 50/100
-
dependencies github-actions
Difficulty 2/5 1-3 hours Newbie friendliness 20/100
-
dependencies github-actions
Difficulty 2/5 1-3 hours Newbie friendliness 10/100
Similar issues
-
area: harness bug status: needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Human-Agent-Society/reef#625 ·
-
module: core
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
bigbluebutton/bigbluebutton#25849 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
vercel-labs/just-bash#464 ·
-
area:sandbox documentation enhancement platform:linux
Difficulty 1/5 Under an hour Newbie friendliness 85/100
anthropics/claude-code#96664 ·
-
cost:cheap severity:medium
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
fairagro/m4.2_sql_to_arc#227 ·