Skip to content

Repository files navigation

Note

DriveWealth fork — This is not a true fork. It is a shim that replaces the upstream Docker-based action with a composite action that downloads the official mszostok/codeowners-validator binary directly from GitHub Releases, enabling ARM64 runner support.

  • Pinned to v0.7.2 to avoid the GitHub App token scope regression in v0.7.3+ (see upstream issue #143)
  • The upstream Docker image (ghcr.io/mszostok/codeowners-validator:v0.7.2) is AMD64-only; v0.7.2 ships a Linux_arm64 binary which this action uses instead
  • Reference as DriveWealth/codeowners-validator@<sha> — do not use a tag, tags point to the upstream release, not this shim

Tracked in DO-7299.



logo

Ensures the correctness of your CODEOWNERS file.





Codeowners Validator

Software LicenseGo Report CardTwitter Follow

The Codeowners Validator project validates the GitHub CODEOWNERS file based on specified checks. It supports public and private GitHub repositories and also GitHub Enterprise installations.

usage

Usage

Docker

export GH_TOKEN=<your_token>
docker run --rm -v $(pwd):/repo -w /repo \
-e REPOSITORY_PATH="." \
-e GITHUB_ACCESS_TOKEN="$GH_TOKEN" \
-e EXPERIMENTAL_CHECKS="notowned" \
-e OWNER_CHECKER_REPOSITORY="org-name/rep-name" \
mszostok/codeowners-validator:v0.7.2

Command line

export GH_TOKEN=<your_token>
env REPOSITORY_PATH="." \
GITHUB_ACCESS_TOKEN="$GH_TOKEN" \
EXPERIMENTAL_CHECKS="notowned" \
OWNER_CHECKER_REPOSITORY="org-name/rep-name" \
codeowners-validator

GitHub Action

- uses: mszostok/codeowners-validator@v0.7.2with:
checks: "files,owners,duppatterns"experimental_checks: "notowned"# GitHub access token is required only if the `owners` check is enabledgithub_access_token: "${{ secrets.OWNERS_VALIDATOR_GITHUB_SECRET }}"

Check this document for more information about GitHub Action.


Check the Configuration section for more info on how to enable and configure given checks.

Installation

It's highly recommended to install a fixed version of codeowners-validator. Releases are available on the releases page.

From Release

Here is the recommended way to install codeowners-validator:

# binary installed into ./bin/
curl -sfL https://raw.githubusercontent.com/mszostok/codeowners-validator/main/install.sh | sh -s v0.7.2
# binary installed into $(go env GOPATH)/bin/codeowners-validator
curl -sfL https://raw.githubusercontent.com/mszostok/codeowners-validator/main/install.sh | sh -s -- -b $(go env GOPATH)/bin v0.7.2
# In alpine linux (as it does not come with curl by default)
wget -O - -q https://raw.githubusercontent.com/mszostok/codeowners-validator/main/install.sh | sh -s v0.7.2
# Print version. Add `--short` to print just the version number.
codeowners-validator -v

You can also download latest version from release page manually.

From Sources

You can install codeowners-validator with go install github.com/mszostok/codeowners-validator@v0.7.2.

NOTE: please use Go 1.16 or greater.

This will put codeowners-validator in $(go env GOPATH)/bin.

Checks

The following checks are enabled by default:

NameDescription
duppatterns[Duplicated Pattern Checker]

Reports if CODEOWNERS file contain duplicated lines with the same file pattern.
files[File Exist Checker]

Reports if CODEOWNERS file contain lines with the file pattern that do not exist in a given repository.
owners[Valid Owner Checker]

Reports if CODEOWNERS file contain invalid owners definition. Allowed owner syntax: @username, @org/team-name or user@example.com
source: https://help.github.com/articles/about-code-owners/#codeowners-syntax.

Checks:
1. Check if the owner's definition is valid (is either a GitHub user name, an organization team name or an email address).

2. Check if a GitHub owner has a GitHub account

3. Check if a GitHub owner is in a given organization

4. Check if an organization team exists
syntax[Valid Syntax Checker]

Reports if CODEOWNERS file contain invalid syntax definition. It is imported as:
"If any line in your CODEOWNERS file contains invalid syntax, the file will not be detected
and will not be used to request reviews. Invalid syntax includes inline comments
and user or team names that do not exist on GitHub."

source: https://help.github.com/articles/about-code-owners/#codeowners-syntax.

The experimental checks are disabled by default:

NameDescription
notowned[Not Owned File Checker]

Reports if a given repository contain files that do not have specified owners in CODEOWNERS file.

To enable experimental check set EXPERIMENTAL_CHECKS=notowned environment variable.

Check the Configuration section for more info on how to enable and configure given checks.

Configuration

Use the following environment variables to configure the application:

NameDefaultDescription
REPOSITORY_PATH*Path to your repository on your local machine.
GITHUB_ACCESS_TOKENGitHub access token. Instruction for creating a token can be found here. If not provided, the owners validating functionality may not work properly. For example, you may reach the API calls quota or, if you are setting GitHub Enterprise base URL, an unauthorized error may occur.
GITHUB_BASE_URLhttps://api.github.com/GitHub base URL for API requests. Defaults to the public GitHub API but can be set to a domain endpoint to use with GitHub Enterprise.
GITHUB_UPLOAD_URLhttps://uploads.github.com/GitHub upload URL for uploading files.

It is taken into account only when GITHUB_BASE_URL is also set. If only GITHUB_BASE_URL is provided, this parameter defaults to the GITHUB_BASE_URL value.
CHECKS-List of checks to be executed. By default, all checks are executed. Possible values: files,owners,duppatterns,syntax.
EXPERIMENTAL_CHECKS-The comma-separated list of experimental checks that should be executed. By default, all experimental checks are turned off. Possible values: notowned.
CHECK_FAILURE_LEVELwarningDefines the level on which the application should treat check issues as failures. Defaults to warning, which treats both errors and warnings as failures, and exits with error code 3. Possible values are error and warning.
OWNER_CHECKER_REPOSITORY*The owner and repository name separated by slash. For example, gh-codeowners/codeowners-samples. Used to check if GitHub owner is in the given organization.
OWNER_CHECKER_IGNORED_OWNERS@ghostThe comma-separated list of owners that should not be validated. Example: "@owner1,@owner2,@org/team1,example@email.com".
OWNER_CHECKER_ALLOW_UNOWNED_PATTERNStrueSpecifies whether CODEOWNERS may have unowned files. For example:

/infra/oncall-rotator/ @sre-team
/infra/oncall-rotator/oncall-config.yml

The /infra/oncall-rotator/oncall-config.yml file is not owned by anyone.
OWNER_CHEKER_OWNERS_MUST_BE_TEAMSfalseSpecifies whether only teams are allowed as owners of files.
NOT_OWNED_CHECKER_SKIP_PATTERNS-The comma-separated list of patterns that should be ignored by not-owned-checker. For example, you can specify * and as a result, the * pattern from the CODEOWNERS file will be ignored and files owned by this pattern will be reported as unowned unless a later specific pattern will match that path. It's useful because often we have default owners entry at the begging of the CODOEWNERS file, e.g. * @global-owner1 @global-owner2

* - Required

Exit status codes

Application exits with different status codes which allow you to easily distinguish between error categories.

CodeDescription
1The application startup failed due to the wrong configuration or internal error.
2The application was closed because the OS sends a termination signal (SIGINT or SIGTERM).
3The CODEOWNERS validation failed - executed checks found some issues.

Contributing

Contributions are greatly appreciated! The project follows the typical GitHub pull request model. See CONTRIBUTING.md for more details.

Roadmap

The codeowners-validator roadmap uses GitHub milestones to track the progress of the project.

They are sorted with priority. First are most important.

About

Fork of mszostok/codeowners-validator — patched for ARM64 runner support. Pinned to v0.7.2 base to avoid token scope regression in v0.7.3+ (DO-7299).

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages