From f4eba61a2733a19c5ccd9a9e5c598c9dd50946a0 Mon Sep 17 00:00:00 2001 From: Pigbibi <20649888+Pigbibi@users.noreply.github.com> Date: Tue, 29 Sep 2026 01:21:19 +0800 Subject: [PATCH] fix: route dependency review without personal requests Co-Authored-By: Codex --- .github/CODEOWNERS | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index cc3b5b4..49b3384 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1,7 +1,14 @@ # Token refresh, workflow, and dependency changes require owner visibility. /.github/CODEOWNERS @Pigbibi -/.github/workflows/ @Pigbibi /main.js @Pigbibi /lib/ @Pigbibi -/package.json @Pigbibi -/package-lock.json @Pigbibi + +# Dependency paths below do not automatically request a personal review. +# They still require scoped engineering review, passing CI, and applicable +# compatibility/recovery evidence. Disabled generic auto-merge stays disabled. +# This routing change grants no deployment, credential, or investment authority. +# Engineering review scope: /.github/workflows/ +# Engineering review scope: /package-lock.json +# Engineering review scope: /package.json +# The AIAuditBridge dependency lane only covers its existing exact allowlist; +# other dependency/workflow updates remain blocked from unattended adoption.