compute-guard: Hub conditions (90-day cap, named approver, CODEOWNERS, engine-port noise cut)
- non-structural exemptions need approved_by (windy-hub|windy-mind) and expire within 90 days; a longer amnesty simply does not apply and is reported (OVER-CAP). compute-door/guard-self: yearly. - .github/CODEOWNERS on the allow-lists + guard. - engine-port rule skips contracts/schemas/specs/openapi dirs and *.json (53 baseline hits, was 57). - tests: findings carry kind+name never the value; shipped allow file obeys its own rules. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
7
.github/CODEOWNERS
vendored
Normal file
7
.github/CODEOWNERS
vendored
Normal file
@@ -0,0 +1,7 @@
|
||||
# Changes to the guard allow-lists / exemptions need review by the account owner on GitHub, AND an
|
||||
# approved_by (windy-hub | windy-mind) on every non-structural entry, which the guard enforces itself
|
||||
# (scripts/compute_guard.py: load_allow). A lane never approves its own exemption (Hub 10-02).
|
||||
/ci/compute-guard-allow.yml @sneakyfree
|
||||
/ci/secret-guard-allow.yml @sneakyfree
|
||||
/ci/ci-hygiene-allow.yml @sneakyfree
|
||||
/scripts/compute_guard.py @sneakyfree
|
||||
Reference in New Issue
Block a user