Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

CODEOWNERS Guard

CODEOWNERS Guard

Fast, GitHub-native validation for the CODEOWNERS file that GitHub will actually use.

CICodeQLRelease buildLatest releaseDownloadsLicenseNode.js 24 or newerGitHub Action runtime: Node.js 24Platforms: Windows, Linux, and macOS

Last commit on mainOpen issues

CODEOWNERS Guard combines GitHub's own diagnostics with local repository checks. It runs as a native Node.js action, so it works on Linux, macOS, and Windows without pulling a container image.

Why Guard

  • GitHub is the syntax authority. Diagnostics come from the same CODEOWNERS API that evaluates the selected branch, tag, or commit.
  • Local checks cover the gaps. Duplicate patterns, rules that match no tracked file, and files without an effective owner are reported separately.
  • Action-first feedback. Findings become file annotations and a job summary, with counts exposed as workflow outputs.
  • No container startup. The Action runs directly on Node.js 24 on Linux, macOS, and Windows runners.
  • Useful outside Actions. The same core ships as a cross-platform CLI with deterministic text and JSON output.

Checks

CheckWhat it reportsSeverity
syntaxErrors returned by GitHub's CODEOWNERS API for the selected refError
duplicatesA pattern that appears more than onceWarning
danglingA pattern that matches no tracked fileWarning
unownedA tracked file with no effective owner, including files cleared by an ownerless ruleWarning

Rules use GitHub's last-match-wins behavior. CODEOWNERS Guard searches the standard locations in GitHub's order: .github/CODEOWNERS, CODEOWNERS, then docs/CODEOWNERS.

When the syntax check is disabled, local checks assume the remaining CODEOWNERS lines are valid. Keep syntax enabled in the Action, or validate the committed ref with GitHub before relying on local-only coverage results.

See the check reference for exact matching, exclusion, and result-limit behavior.

GitHub Action

name: CODEOWNERSon:
pull_request:
push:
branches: [main]permissions:
contents: readjobs:
validate:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: rarepops/codeowners-guard@v0.1.1with:
checks: syntax,duplicates,dangling,unownedexclude: | dist/ coverage/

For the strongest supply-chain pinning, replace v0.1.1 with its full commit SHA. A complete least-privilege workflow is available in examples/codeowners.yml.

Released tags are exercised from the independent public integration repository.

The action adds file annotations and a job summary. Its default token is ${{ github.token }}, and the workflow only needs contents: read.

The Action takes its API endpoint from GitHub's runner environment. It does not accept an endpoint input that could redirect the automatically supplied token. GitHub Enterprise Server runners provide their own trusted GITHUB_API_URL.

Inputs

InputDefaultDescription
github-token${{ github.token }}Token used for GitHub diagnostics
path.Repository path relative to GITHUB_WORKSPACE
codeownersauto-detectExplicit CODEOWNERS path
checksall checksComma-separated checks
excludenoneNewline-separated gitignore patterns omitted from local checks
repository${{ github.repository }}Repository in owner/name form
ref${{ github.sha }}Branch, tag, or commit used by the syntax check
fail-onwarningFailure threshold: warning or error
max-annotations50Maximum workflow annotations and summary rows, up to 100

Annotation limits do not change validation counts or failure behavior.

Outputs

The action returns valid, issue-count, error-count, and warning-count.

CLI

Run the published CLI without installing it globally:

npx --yes codeowners-guard@0.1.1 . --checks duplicates,dangling,unowned

Use codeowners-guard@latest instead when you explicitly want the newest release. Pinning a version keeps local and CI runs reproducible.

Build and run the CLI locally:

npm ci
npm run build
node dist/cli.js .

Local checks require no network access:

node dist/cli.js . \
--checks duplicates,dangling,unowned \
--exclude dist/ \
--format json

GitHub's syntax check validates a committed branch, tag, or SHA:

GITHUB_TOKEN=ghp_example node dist/cli.js . \
--checks syntax,duplicates,dangling,unowned \
--repository owner/repository \
--ref main

Tokens are accepted only through GITHUB_TOKEN or GH_TOKEN; command-line token arguments are deliberately unsupported so credentials do not enter shell history or process listings.

Use --max-issues to retain up to 10,000 issue details in text or JSON output. The default is 1,000. Use --fail-on error to report local warnings without returning a failing exit status. Exit code 1 means validation failed, and exit code 2 means the command could not run.

See troubleshooting for authentication, ref mismatch, missing file, and exit-code guidance.

Design

GitHub remains the authority for syntax diagnostics. Local checks operate on files returned by git ls-files, use a maintained gitignore-compatible matcher, and do not make separate user or team lookup calls. This keeps the Action small and avoids maintaining a second copy of GitHub's owner-resolution behavior.

The syntax check targets ref, while local checks target the checked-out working tree. In normal Actions usage both refer to the same commit. For uncommitted local changes, run local checks only or push the change to a ref before requesting GitHub diagnostics.

Security

  • GitHub workflow dependencies are pinned to immutable commit SHAs, and repository settings require SHA-pinned Actions.
  • API calls require HTTPS, reject redirects, time out after 15 seconds, cap responses at 1 MiB, and retry only bounded transient failures.
  • Action paths and CODEOWNERS files cannot escape the checked-out workspace through traversal or symbolic links.
  • Terminal text, workflow annotations, and HTML summaries escape control and bidirectional characters.
  • Dependency installation disables lifecycle scripts; CI checks advisories, registry signatures, and dependency diffs.
  • Tagged release artifacts include SHA-256 checksums and GitHub build-provenance attestations.

Performance

  • Tracked paths stream from git ls-files -z, avoiding a fixed child-process output buffer.
  • GitHub diagnostics and tracked-file enumeration run concurrently.
  • Each file is normalized once and evaluated against ownership rules in one pass, while duplicate-only checks skip Git entirely.
  • Finding details are retained within configured bounds while exact counts and failure behavior cover every finding.
  • npm run bench measures a 10,000-rule duplicate workload and a 10,000-file by 100-rule ownership workload.

Development

Requires Node.js 24 or newer.

npm ci
npm run check
npm run bench

npm run check includes linting, strict type checking, tests with coverage thresholds, and a production build. dist/ is committed because GitHub executes JavaScript actions directly from the repository. CI rejects source changes that do not include rebuilt bundles and third-party notices.

License

CODEOWNERS Guard is source-available under the PolyForm Perimeter License 1.0.1. The license permits use, modification, and redistribution, but does not permit using the software to provide a competing product. Review the license terms before adopting or redistributing the project.

Licenses for packages embedded in the distributed bundles are reproduced in THIRD_PARTY_NOTICES.md.

Copyright (c) 2026 Rares (rarepops).

About

GitHub-native CODEOWNERS validation: authoritative diagnostics, duplicate and dangling rules, and unowned tracked files. Node 24 Action and CLI.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

CODEOWNERS Guard

CODEOWNERS Guard

Fast, GitHub-native validation for the CODEOWNERS file that GitHub will actually use.

CICodeQLRelease buildLatest releaseDownloadsLicenseNode.js 24 or newerGitHub Action runtime: Node.js 24Platforms: Windows, Linux, and macOS

Last commit on mainOpen issues

CODEOWNERS Guard combines GitHub's own diagnostics with local repository checks. It runs as a native Node.js action, so it works on Linux, macOS, and Windows without pulling a container image.

Why Guard

  • GitHub is the syntax authority. Diagnostics come from the same CODEOWNERS API that evaluates the selected branch, tag, or commit.
  • Local checks cover the gaps. Duplicate patterns, rules that match no tracked file, and files without an effective owner are reported separately.
  • Action-first feedback. Findings become file annotations and a job summary, with counts exposed as workflow outputs.
  • No container startup. The Action runs directly on Node.js 24 on Linux, macOS, and Windows runners.
  • Useful outside Actions. The same core ships as a cross-platform CLI with deterministic text and JSON output.

Checks

CheckWhat it reportsSeverity
syntaxErrors returned by GitHub's CODEOWNERS API for the selected refError
duplicatesA pattern that appears more than onceWarning
danglingA pattern that matches no tracked fileWarning
unownedA tracked file with no effective owner, including files cleared by an ownerless ruleWarning

Rules use GitHub's last-match-wins behavior. CODEOWNERS Guard searches the standard locations in GitHub's order: .github/CODEOWNERS, CODEOWNERS, then docs/CODEOWNERS.

When the syntax check is disabled, local checks assume the remaining CODEOWNERS lines are valid. Keep syntax enabled in the Action, or validate the committed ref with GitHub before relying on local-only coverage results.

See the check reference for exact matching, exclusion, and result-limit behavior.

GitHub Action

name: CODEOWNERSon:
pull_request:
push:
branches: [main]permissions:
contents: readjobs:
validate:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: rarepops/codeowners-guard@v0.1.1with:
checks: syntax,duplicates,dangling,unownedexclude: | dist/ coverage/

For the strongest supply-chain pinning, replace v0.1.1 with its full commit SHA. A complete least-privilege workflow is available in examples/codeowners.yml.

Released tags are exercised from the independent public integration repository.

The action adds file annotations and a job summary. Its default token is ${{ github.token }}, and the workflow only needs contents: read.

The Action takes its API endpoint from GitHub's runner environment. It does not accept an endpoint input that could redirect the automatically supplied token. GitHub Enterprise Server runners provide their own trusted GITHUB_API_URL.

Inputs

InputDefaultDescription
github-token${{ github.token }}Token used for GitHub diagnostics
path.Repository path relative to GITHUB_WORKSPACE
codeownersauto-detectExplicit CODEOWNERS path
checksall checksComma-separated checks
excludenoneNewline-separated gitignore patterns omitted from local checks
repository${{ github.repository }}Repository in owner/name form
ref${{ github.sha }}Branch, tag, or commit used by the syntax check
fail-onwarningFailure threshold: warning or error
max-annotations50Maximum workflow annotations and summary rows, up to 100

Annotation limits do not change validation counts or failure behavior.

Outputs

The action returns valid, issue-count, error-count, and warning-count.

CLI

Run the published CLI without installing it globally:

npx --yes codeowners-guard@0.1.1 . --checks duplicates,dangling,unowned

Use codeowners-guard@latest instead when you explicitly want the newest release. Pinning a version keeps local and CI runs reproducible.

Build and run the CLI locally:

npm ci
npm run build
node dist/cli.js .

Local checks require no network access:

node dist/cli.js . \
--checks duplicates,dangling,unowned \
--exclude dist/ \
--format json

GitHub's syntax check validates a committed branch, tag, or SHA:

GITHUB_TOKEN=ghp_example node dist/cli.js . \
--checks syntax,duplicates,dangling,unowned \
--repository owner/repository \
--ref main

Tokens are accepted only through GITHUB_TOKEN or GH_TOKEN; command-line token arguments are deliberately unsupported so credentials do not enter shell history or process listings.

Use --max-issues to retain up to 10,000 issue details in text or JSON output. The default is 1,000. Use --fail-on error to report local warnings without returning a failing exit status. Exit code 1 means validation failed, and exit code 2 means the command could not run.

See troubleshooting for authentication, ref mismatch, missing file, and exit-code guidance.

Design

GitHub remains the authority for syntax diagnostics. Local checks operate on files returned by git ls-files, use a maintained gitignore-compatible matcher, and do not make separate user or team lookup calls. This keeps the Action small and avoids maintaining a second copy of GitHub's owner-resolution behavior.

The syntax check targets ref, while local checks target the checked-out working tree. In normal Actions usage both refer to the same commit. For uncommitted local changes, run local checks only or push the change to a ref before requesting GitHub diagnostics.

Security

  • GitHub workflow dependencies are pinned to immutable commit SHAs, and repository settings require SHA-pinned Actions.
  • API calls require HTTPS, reject redirects, time out after 15 seconds, cap responses at 1 MiB, and retry only bounded transient failures.
  • Action paths and CODEOWNERS files cannot escape the checked-out workspace through traversal or symbolic links.
  • Terminal text, workflow annotations, and HTML summaries escape control and bidirectional characters.
  • Dependency installation disables lifecycle scripts; CI checks advisories, registry signatures, and dependency diffs.
  • Tagged release artifacts include SHA-256 checksums and GitHub build-provenance attestations.

Performance

  • Tracked paths stream from git ls-files -z, avoiding a fixed child-process output buffer.
  • GitHub diagnostics and tracked-file enumeration run concurrently.
  • Each file is normalized once and evaluated against ownership rules in one pass, while duplicate-only checks skip Git entirely.
  • Finding details are retained within configured bounds while exact counts and failure behavior cover every finding.
  • npm run bench measures a 10,000-rule duplicate workload and a 10,000-file by 100-rule ownership workload.

Development

Requires Node.js 24 or newer.

npm ci
npm run check
npm run bench

npm run check includes linting, strict type checking, tests with coverage thresholds, and a production build. dist/ is committed because GitHub executes JavaScript actions directly from the repository. CI rejects source changes that do not include rebuilt bundles and third-party notices.

License

CODEOWNERS Guard is source-available under the PolyForm Perimeter License 1.0.1. The license permits use, modification, and redistribution, but does not permit using the software to provide a competing product. Review the license terms before adopting or redistributing the project.

Licenses for packages embedded in the distributed bundles are reproduced in THIRD_PARTY_NOTICES.md.

Copyright (c) 2026 Rares (rarepops).

About

GitHub-native CODEOWNERS validation: authoritative diagnostics, duplicate and dangling rules, and unowned tracked files. Node 24 Action and CLI.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

CODEOWNERS Guard

CODEOWNERS Guard

Fast, GitHub-native validation for the CODEOWNERS file that GitHub will actually use.

CICodeQLRelease buildLatest releaseDownloadsLicenseNode.js 24 or newerGitHub Action runtime: Node.js 24Platforms: Windows, Linux, and macOS

Last commit on mainOpen issues

CODEOWNERS Guard combines GitHub's own diagnostics with local repository checks. It runs as a native Node.js action, so it works on Linux, macOS, and Windows without pulling a container image.

Why Guard

  • GitHub is the syntax authority. Diagnostics come from the same CODEOWNERS API that evaluates the selected branch, tag, or commit.
  • Local checks cover the gaps. Duplicate patterns, rules that match no tracked file, and files without an effective owner are reported separately.
  • Action-first feedback. Findings become file annotations and a job summary, with counts exposed as workflow outputs.
  • No container startup. The Action runs directly on Node.js 24 on Linux, macOS, and Windows runners.
  • Useful outside Actions. The same core ships as a cross-platform CLI with deterministic text and JSON output.

Checks

CheckWhat it reportsSeverity
syntaxErrors returned by GitHub's CODEOWNERS API for the selected refError
duplicatesA pattern that appears more than onceWarning
danglingA pattern that matches no tracked fileWarning
unownedA tracked file with no effective owner, including files cleared by an ownerless ruleWarning

Rules use GitHub's last-match-wins behavior. CODEOWNERS Guard searches the standard locations in GitHub's order: .github/CODEOWNERS, CODEOWNERS, then docs/CODEOWNERS.

When the syntax check is disabled, local checks assume the remaining CODEOWNERS lines are valid. Keep syntax enabled in the Action, or validate the committed ref with GitHub before relying on local-only coverage results.

See the check reference for exact matching, exclusion, and result-limit behavior.

GitHub Action

name: CODEOWNERSon:
pull_request:
push:
branches: [main]permissions:
contents: readjobs:
validate:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: rarepops/codeowners-guard@v0.1.1with:
checks: syntax,duplicates,dangling,unownedexclude: | dist/ coverage/

For the strongest supply-chain pinning, replace v0.1.1 with its full commit SHA. A complete least-privilege workflow is available in examples/codeowners.yml.

Released tags are exercised from the independent public integration repository.

The action adds file annotations and a job summary. Its default token is ${{ github.token }}, and the workflow only needs contents: read.

The Action takes its API endpoint from GitHub's runner environment. It does not accept an endpoint input that could redirect the automatically supplied token. GitHub Enterprise Server runners provide their own trusted GITHUB_API_URL.

Inputs

InputDefaultDescription
github-token${{ github.token }}Token used for GitHub diagnostics
path.Repository path relative to GITHUB_WORKSPACE
codeownersauto-detectExplicit CODEOWNERS path
checksall checksComma-separated checks
excludenoneNewline-separated gitignore patterns omitted from local checks
repository${{ github.repository }}Repository in owner/name form
ref${{ github.sha }}Branch, tag, or commit used by the syntax check
fail-onwarningFailure threshold: warning or error
max-annotations50Maximum workflow annotations and summary rows, up to 100

Annotation limits do not change validation counts or failure behavior.

Outputs

The action returns valid, issue-count, error-count, and warning-count.

CLI

Run the published CLI without installing it globally:

npx --yes codeowners-guard@0.1.1 . --checks duplicates,dangling,unowned

Use codeowners-guard@latest instead when you explicitly want the newest release. Pinning a version keeps local and CI runs reproducible.

Build and run the CLI locally:

npm ci
npm run build
node dist/cli.js .

Local checks require no network access:

node dist/cli.js . \
--checks duplicates,dangling,unowned \
--exclude dist/ \
--format json

GitHub's syntax check validates a committed branch, tag, or SHA:

GITHUB_TOKEN=ghp_example node dist/cli.js . \
--checks syntax,duplicates,dangling,unowned \
--repository owner/repository \
--ref main

Tokens are accepted only through GITHUB_TOKEN or GH_TOKEN; command-line token arguments are deliberately unsupported so credentials do not enter shell history or process listings.

Use --max-issues to retain up to 10,000 issue details in text or JSON output. The default is 1,000. Use --fail-on error to report local warnings without returning a failing exit status. Exit code 1 means validation failed, and exit code 2 means the command could not run.

See troubleshooting for authentication, ref mismatch, missing file, and exit-code guidance.

Design

GitHub remains the authority for syntax diagnostics. Local checks operate on files returned by git ls-files, use a maintained gitignore-compatible matcher, and do not make separate user or team lookup calls. This keeps the Action small and avoids maintaining a second copy of GitHub's owner-resolution behavior.

The syntax check targets ref, while local checks target the checked-out working tree. In normal Actions usage both refer to the same commit. For uncommitted local changes, run local checks only or push the change to a ref before requesting GitHub diagnostics.

Security

  • GitHub workflow dependencies are pinned to immutable commit SHAs, and repository settings require SHA-pinned Actions.
  • API calls require HTTPS, reject redirects, time out after 15 seconds, cap responses at 1 MiB, and retry only bounded transient failures.
  • Action paths and CODEOWNERS files cannot escape the checked-out workspace through traversal or symbolic links.
  • Terminal text, workflow annotations, and HTML summaries escape control and bidirectional characters.
  • Dependency installation disables lifecycle scripts; CI checks advisories, registry signatures, and dependency diffs.
  • Tagged release artifacts include SHA-256 checksums and GitHub build-provenance attestations.

Performance

  • Tracked paths stream from git ls-files -z, avoiding a fixed child-process output buffer.
  • GitHub diagnostics and tracked-file enumeration run concurrently.
  • Each file is normalized once and evaluated against ownership rules in one pass, while duplicate-only checks skip Git entirely.
  • Finding details are retained within configured bounds while exact counts and failure behavior cover every finding.
  • npm run bench measures a 10,000-rule duplicate workload and a 10,000-file by 100-rule ownership workload.

Development

Requires Node.js 24 or newer.

npm ci
npm run check
npm run bench

npm run check includes linting, strict type checking, tests with coverage thresholds, and a production build. dist/ is committed because GitHub executes JavaScript actions directly from the repository. CI rejects source changes that do not include rebuilt bundles and third-party notices.

License

CODEOWNERS Guard is source-available under the PolyForm Perimeter License 1.0.1. The license permits use, modification, and redistribution, but does not permit using the software to provide a competing product. Review the license terms before adopting or redistributing the project.

Licenses for packages embedded in the distributed bundles are reproduced in THIRD_PARTY_NOTICES.md.

Copyright (c) 2026 Rares (rarepops).

About

GitHub-native CODEOWNERS validation: authoritative diagnostics, duplicate and dangling rules, and unowned tracked files. Node 24 Action and CLI.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

CODEOWNERS Guard

CODEOWNERS Guard

Fast, GitHub-native validation for the CODEOWNERS file that GitHub will actually use.

CICodeQLRelease buildLatest releaseDownloadsLicenseNode.js 24 or newerGitHub Action runtime: Node.js 24Platforms: Windows, Linux, and macOS

Last commit on mainOpen issues

CODEOWNERS Guard combines GitHub's own diagnostics with local repository checks. It runs as a native Node.js action, so it works on Linux, macOS, and Windows without pulling a container image.

Why Guard

  • GitHub is the syntax authority. Diagnostics come from the same CODEOWNERS API that evaluates the selected branch, tag, or commit.
  • Local checks cover the gaps. Duplicate patterns, rules that match no tracked file, and files without an effective owner are reported separately.
  • Action-first feedback. Findings become file annotations and a job summary, with counts exposed as workflow outputs.
  • No container startup. The Action runs directly on Node.js 24 on Linux, macOS, and Windows runners.
  • Useful outside Actions. The same core ships as a cross-platform CLI with deterministic text and JSON output.

Checks

CheckWhat it reportsSeverity
syntaxErrors returned by GitHub's CODEOWNERS API for the selected refError
duplicatesA pattern that appears more than onceWarning
danglingA pattern that matches no tracked fileWarning
unownedA tracked file with no effective owner, including files cleared by an ownerless ruleWarning

Rules use GitHub's last-match-wins behavior. CODEOWNERS Guard searches the standard locations in GitHub's order: .github/CODEOWNERS, CODEOWNERS, then docs/CODEOWNERS.

When the syntax check is disabled, local checks assume the remaining CODEOWNERS lines are valid. Keep syntax enabled in the Action, or validate the committed ref with GitHub before relying on local-only coverage results.

See the check reference for exact matching, exclusion, and result-limit behavior.

GitHub Action

name: CODEOWNERSon:
pull_request:
push:
branches: [main]permissions:
contents: readjobs:
validate:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: rarepops/codeowners-guard@v0.1.1with:
checks: syntax,duplicates,dangling,unownedexclude: | dist/ coverage/

For the strongest supply-chain pinning, replace v0.1.1 with its full commit SHA. A complete least-privilege workflow is available in examples/codeowners.yml.

Released tags are exercised from the independent public integration repository.

The action adds file annotations and a job summary. Its default token is ${{ github.token }}, and the workflow only needs contents: read.

The Action takes its API endpoint from GitHub's runner environment. It does not accept an endpoint input that could redirect the automatically supplied token. GitHub Enterprise Server runners provide their own trusted GITHUB_API_URL.

Inputs

InputDefaultDescription
github-token${{ github.token }}Token used for GitHub diagnostics
path.Repository path relative to GITHUB_WORKSPACE
codeownersauto-detectExplicit CODEOWNERS path
checksall checksComma-separated checks
excludenoneNewline-separated gitignore patterns omitted from local checks
repository${{ github.repository }}Repository in owner/name form
ref${{ github.sha }}Branch, tag, or commit used by the syntax check
fail-onwarningFailure threshold: warning or error
max-annotations50Maximum workflow annotations and summary rows, up to 100

Annotation limits do not change validation counts or failure behavior.

Outputs

The action returns valid, issue-count, error-count, and warning-count.

CLI

Run the published CLI without installing it globally:

npx --yes codeowners-guard@0.1.1 . --checks duplicates,dangling,unowned

Use codeowners-guard@latest instead when you explicitly want the newest release. Pinning a version keeps local and CI runs reproducible.

Build and run the CLI locally:

npm ci
npm run build
node dist/cli.js .

Local checks require no network access:

node dist/cli.js . \
--checks duplicates,dangling,unowned \
--exclude dist/ \
--format json

GitHub's syntax check validates a committed branch, tag, or SHA:

GITHUB_TOKEN=ghp_example node dist/cli.js . \
--checks syntax,duplicates,dangling,unowned \
--repository owner/repository \
--ref main

Tokens are accepted only through GITHUB_TOKEN or GH_TOKEN; command-line token arguments are deliberately unsupported so credentials do not enter shell history or process listings.

Use --max-issues to retain up to 10,000 issue details in text or JSON output. The default is 1,000. Use --fail-on error to report local warnings without returning a failing exit status. Exit code 1 means validation failed, and exit code 2 means the command could not run.

See troubleshooting for authentication, ref mismatch, missing file, and exit-code guidance.

Design

GitHub remains the authority for syntax diagnostics. Local checks operate on files returned by git ls-files, use a maintained gitignore-compatible matcher, and do not make separate user or team lookup calls. This keeps the Action small and avoids maintaining a second copy of GitHub's owner-resolution behavior.

The syntax check targets ref, while local checks target the checked-out working tree. In normal Actions usage both refer to the same commit. For uncommitted local changes, run local checks only or push the change to a ref before requesting GitHub diagnostics.

Security

  • GitHub workflow dependencies are pinned to immutable commit SHAs, and repository settings require SHA-pinned Actions.
  • API calls require HTTPS, reject redirects, time out after 15 seconds, cap responses at 1 MiB, and retry only bounded transient failures.
  • Action paths and CODEOWNERS files cannot escape the checked-out workspace through traversal or symbolic links.
  • Terminal text, workflow annotations, and HTML summaries escape control and bidirectional characters.
  • Dependency installation disables lifecycle scripts; CI checks advisories, registry signatures, and dependency diffs.
  • Tagged release artifacts include SHA-256 checksums and GitHub build-provenance attestations.

Performance

  • Tracked paths stream from git ls-files -z, avoiding a fixed child-process output buffer.
  • GitHub diagnostics and tracked-file enumeration run concurrently.
  • Each file is normalized once and evaluated against ownership rules in one pass, while duplicate-only checks skip Git entirely.
  • Finding details are retained within configured bounds while exact counts and failure behavior cover every finding.
  • npm run bench measures a 10,000-rule duplicate workload and a 10,000-file by 100-rule ownership workload.

Development

Requires Node.js 24 or newer.

npm ci
npm run check
npm run bench

npm run check includes linting, strict type checking, tests with coverage thresholds, and a production build. dist/ is committed because GitHub executes JavaScript actions directly from the repository. CI rejects source changes that do not include rebuilt bundles and third-party notices.

License

CODEOWNERS Guard is source-available under the PolyForm Perimeter License 1.0.1. The license permits use, modification, and redistribution, but does not permit using the software to provide a competing product. Review the license terms before adopting or redistributing the project.

Licenses for packages embedded in the distributed bundles are reproduced in THIRD_PARTY_NOTICES.md.

Copyright (c) 2026 Rares (rarepops).

About

GitHub-native CODEOWNERS validation: authoritative diagnostics, duplicate and dangling rules, and unowned tracked files. Node 24 Action and CLI.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

CODEOWNERS Guard

CODEOWNERS Guard

Fast, GitHub-native validation for the CODEOWNERS file that GitHub will actually use.

CICodeQLRelease buildLatest releaseDownloadsLicenseNode.js 24 or newerGitHub Action runtime: Node.js 24Platforms: Windows, Linux, and macOS

Last commit on mainOpen issues

CODEOWNERS Guard combines GitHub's own diagnostics with local repository checks. It runs as a native Node.js action, so it works on Linux, macOS, and Windows without pulling a container image.

Why Guard

  • GitHub is the syntax authority. Diagnostics come from the same CODEOWNERS API that evaluates the selected branch, tag, or commit.
  • Local checks cover the gaps. Duplicate patterns, rules that match no tracked file, and files without an effective owner are reported separately.
  • Action-first feedback. Findings become file annotations and a job summary, with counts exposed as workflow outputs.
  • No container startup. The Action runs directly on Node.js 24 on Linux, macOS, and Windows runners.
  • Useful outside Actions. The same core ships as a cross-platform CLI with deterministic text and JSON output.

Checks

CheckWhat it reportsSeverity
syntaxErrors returned by GitHub's CODEOWNERS API for the selected refError
duplicatesA pattern that appears more than onceWarning
danglingA pattern that matches no tracked fileWarning
unownedA tracked file with no effective owner, including files cleared by an ownerless ruleWarning

Rules use GitHub's last-match-wins behavior. CODEOWNERS Guard searches the standard locations in GitHub's order: .github/CODEOWNERS, CODEOWNERS, then docs/CODEOWNERS.

When the syntax check is disabled, local checks assume the remaining CODEOWNERS lines are valid. Keep syntax enabled in the Action, or validate the committed ref with GitHub before relying on local-only coverage results.

See the check reference for exact matching, exclusion, and result-limit behavior.

GitHub Action

name: CODEOWNERSon:
pull_request:
push:
branches: [main]permissions:
contents: readjobs:
validate:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: rarepops/codeowners-guard@v0.1.1with:
checks: syntax,duplicates,dangling,unownedexclude: | dist/ coverage/

For the strongest supply-chain pinning, replace v0.1.1 with its full commit SHA. A complete least-privilege workflow is available in examples/codeowners.yml.

Released tags are exercised from the independent public integration repository.

The action adds file annotations and a job summary. Its default token is ${{ github.token }}, and the workflow only needs contents: read.

The Action takes its API endpoint from GitHub's runner environment. It does not accept an endpoint input that could redirect the automatically supplied token. GitHub Enterprise Server runners provide their own trusted GITHUB_API_URL.

Inputs

InputDefaultDescription
github-token${{ github.token }}Token used for GitHub diagnostics
path.Repository path relative to GITHUB_WORKSPACE
codeownersauto-detectExplicit CODEOWNERS path
checksall checksComma-separated checks
excludenoneNewline-separated gitignore patterns omitted from local checks
repository${{ github.repository }}Repository in owner/name form
ref${{ github.sha }}Branch, tag, or commit used by the syntax check
fail-onwarningFailure threshold: warning or error
max-annotations50Maximum workflow annotations and summary rows, up to 100

Annotation limits do not change validation counts or failure behavior.

Outputs

The action returns valid, issue-count, error-count, and warning-count.

CLI

Run the published CLI without installing it globally:

npx --yes codeowners-guard@0.1.1 . --checks duplicates,dangling,unowned

Use codeowners-guard@latest instead when you explicitly want the newest release. Pinning a version keeps local and CI runs reproducible.

Build and run the CLI locally:

npm ci
npm run build
node dist/cli.js .

Local checks require no network access:

node dist/cli.js . \
--checks duplicates,dangling,unowned \
--exclude dist/ \
--format json

GitHub's syntax check validates a committed branch, tag, or SHA:

GITHUB_TOKEN=ghp_example node dist/cli.js . \
--checks syntax,duplicates,dangling,unowned \
--repository owner/repository \
--ref main

Tokens are accepted only through GITHUB_TOKEN or GH_TOKEN; command-line token arguments are deliberately unsupported so credentials do not enter shell history or process listings.

Use --max-issues to retain up to 10,000 issue details in text or JSON output. The default is 1,000. Use --fail-on error to report local warnings without returning a failing exit status. Exit code 1 means validation failed, and exit code 2 means the command could not run.

See troubleshooting for authentication, ref mismatch, missing file, and exit-code guidance.

Design

GitHub remains the authority for syntax diagnostics. Local checks operate on files returned by git ls-files, use a maintained gitignore-compatible matcher, and do not make separate user or team lookup calls. This keeps the Action small and avoids maintaining a second copy of GitHub's owner-resolution behavior.

The syntax check targets ref, while local checks target the checked-out working tree. In normal Actions usage both refer to the same commit. For uncommitted local changes, run local checks only or push the change to a ref before requesting GitHub diagnostics.

Security

  • GitHub workflow dependencies are pinned to immutable commit SHAs, and repository settings require SHA-pinned Actions.
  • API calls require HTTPS, reject redirects, time out after 15 seconds, cap responses at 1 MiB, and retry only bounded transient failures.
  • Action paths and CODEOWNERS files cannot escape the checked-out workspace through traversal or symbolic links.
  • Terminal text, workflow annotations, and HTML summaries escape control and bidirectional characters.
  • Dependency installation disables lifecycle scripts; CI checks advisories, registry signatures, and dependency diffs.
  • Tagged release artifacts include SHA-256 checksums and GitHub build-provenance attestations.

Performance

  • Tracked paths stream from git ls-files -z, avoiding a fixed child-process output buffer.
  • GitHub diagnostics and tracked-file enumeration run concurrently.
  • Each file is normalized once and evaluated against ownership rules in one pass, while duplicate-only checks skip Git entirely.
  • Finding details are retained within configured bounds while exact counts and failure behavior cover every finding.
  • npm run bench measures a 10,000-rule duplicate workload and a 10,000-file by 100-rule ownership workload.

Development

Requires Node.js 24 or newer.

npm ci
npm run check
npm run bench

npm run check includes linting, strict type checking, tests with coverage thresholds, and a production build. dist/ is committed because GitHub executes JavaScript actions directly from the repository. CI rejects source changes that do not include rebuilt bundles and third-party notices.

License

CODEOWNERS Guard is source-available under the PolyForm Perimeter License 1.0.1. The license permits use, modification, and redistribution, but does not permit using the software to provide a competing product. Review the license terms before adopting or redistributing the project.

Licenses for packages embedded in the distributed bundles are reproduced in THIRD_PARTY_NOTICES.md.

Copyright (c) 2026 Rares (rarepops).

About

GitHub-native CODEOWNERS validation: authoritative diagnostics, duplicate and dangling rules, and unowned tracked files. Node 24 Action and CLI.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

CODEOWNERS Guard

CODEOWNERS Guard

Fast, GitHub-native validation for the CODEOWNERS file that GitHub will actually use.

CICodeQLRelease buildLatest releaseDownloadsLicenseNode.js 24 or newerGitHub Action runtime: Node.js 24Platforms: Windows, Linux, and macOS

Last commit on mainOpen issues

CODEOWNERS Guard combines GitHub's own diagnostics with local repository checks. It runs as a native Node.js action, so it works on Linux, macOS, and Windows without pulling a container image.

Why Guard

  • GitHub is the syntax authority. Diagnostics come from the same CODEOWNERS API that evaluates the selected branch, tag, or commit.
  • Local checks cover the gaps. Duplicate patterns, rules that match no tracked file, and files without an effective owner are reported separately.
  • Action-first feedback. Findings become file annotations and a job summary, with counts exposed as workflow outputs.
  • No container startup. The Action runs directly on Node.js 24 on Linux, macOS, and Windows runners.
  • Useful outside Actions. The same core ships as a cross-platform CLI with deterministic text and JSON output.

Checks

CheckWhat it reportsSeverity
syntaxErrors returned by GitHub's CODEOWNERS API for the selected refError
duplicatesA pattern that appears more than onceWarning
danglingA pattern that matches no tracked fileWarning
unownedA tracked file with no effective owner, including files cleared by an ownerless ruleWarning

Rules use GitHub's last-match-wins behavior. CODEOWNERS Guard searches the standard locations in GitHub's order: .github/CODEOWNERS, CODEOWNERS, then docs/CODEOWNERS.

When the syntax check is disabled, local checks assume the remaining CODEOWNERS lines are valid. Keep syntax enabled in the Action, or validate the committed ref with GitHub before relying on local-only coverage results.

See the check reference for exact matching, exclusion, and result-limit behavior.

GitHub Action

name: CODEOWNERSon:
pull_request:
push:
branches: [main]permissions:
contents: readjobs:
validate:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: rarepops/codeowners-guard@v0.1.1with:
checks: syntax,duplicates,dangling,unownedexclude: | dist/ coverage/

For the strongest supply-chain pinning, replace v0.1.1 with its full commit SHA. A complete least-privilege workflow is available in examples/codeowners.yml.

Released tags are exercised from the independent public integration repository.

The action adds file annotations and a job summary. Its default token is ${{ github.token }}, and the workflow only needs contents: read.

The Action takes its API endpoint from GitHub's runner environment. It does not accept an endpoint input that could redirect the automatically supplied token. GitHub Enterprise Server runners provide their own trusted GITHUB_API_URL.

Inputs

InputDefaultDescription
github-token${{ github.token }}Token used for GitHub diagnostics
path.Repository path relative to GITHUB_WORKSPACE
codeownersauto-detectExplicit CODEOWNERS path
checksall checksComma-separated checks
excludenoneNewline-separated gitignore patterns omitted from local checks
repository${{ github.repository }}Repository in owner/name form
ref${{ github.sha }}Branch, tag, or commit used by the syntax check
fail-onwarningFailure threshold: warning or error
max-annotations50Maximum workflow annotations and summary rows, up to 100

Annotation limits do not change validation counts or failure behavior.

Outputs

The action returns valid, issue-count, error-count, and warning-count.

CLI

Run the published CLI without installing it globally:

npx --yes codeowners-guard@0.1.1 . --checks duplicates,dangling,unowned

Use codeowners-guard@latest instead when you explicitly want the newest release. Pinning a version keeps local and CI runs reproducible.

Build and run the CLI locally:

npm ci
npm run build
node dist/cli.js .

Local checks require no network access:

node dist/cli.js . \
--checks duplicates,dangling,unowned \
--exclude dist/ \
--format json

GitHub's syntax check validates a committed branch, tag, or SHA:

GITHUB_TOKEN=ghp_example node dist/cli.js . \
--checks syntax,duplicates,dangling,unowned \
--repository owner/repository \
--ref main

Tokens are accepted only through GITHUB_TOKEN or GH_TOKEN; command-line token arguments are deliberately unsupported so credentials do not enter shell history or process listings.

Use --max-issues to retain up to 10,000 issue details in text or JSON output. The default is 1,000. Use --fail-on error to report local warnings without returning a failing exit status. Exit code 1 means validation failed, and exit code 2 means the command could not run.

See troubleshooting for authentication, ref mismatch, missing file, and exit-code guidance.

Design

GitHub remains the authority for syntax diagnostics. Local checks operate on files returned by git ls-files, use a maintained gitignore-compatible matcher, and do not make separate user or team lookup calls. This keeps the Action small and avoids maintaining a second copy of GitHub's owner-resolution behavior.

The syntax check targets ref, while local checks target the checked-out working tree. In normal Actions usage both refer to the same commit. For uncommitted local changes, run local checks only or push the change to a ref before requesting GitHub diagnostics.

Security

  • GitHub workflow dependencies are pinned to immutable commit SHAs, and repository settings require SHA-pinned Actions.
  • API calls require HTTPS, reject redirects, time out after 15 seconds, cap responses at 1 MiB, and retry only bounded transient failures.
  • Action paths and CODEOWNERS files cannot escape the checked-out workspace through traversal or symbolic links.
  • Terminal text, workflow annotations, and HTML summaries escape control and bidirectional characters.
  • Dependency installation disables lifecycle scripts; CI checks advisories, registry signatures, and dependency diffs.
  • Tagged release artifacts include SHA-256 checksums and GitHub build-provenance attestations.

Performance

  • Tracked paths stream from git ls-files -z, avoiding a fixed child-process output buffer.
  • GitHub diagnostics and tracked-file enumeration run concurrently.
  • Each file is normalized once and evaluated against ownership rules in one pass, while duplicate-only checks skip Git entirely.
  • Finding details are retained within configured bounds while exact counts and failure behavior cover every finding.
  • npm run bench measures a 10,000-rule duplicate workload and a 10,000-file by 100-rule ownership workload.

Development

Requires Node.js 24 or newer.

npm ci
npm run check
npm run bench

npm run check includes linting, strict type checking, tests with coverage thresholds, and a production build. dist/ is committed because GitHub executes JavaScript actions directly from the repository. CI rejects source changes that do not include rebuilt bundles and third-party notices.

License

CODEOWNERS Guard is source-available under the PolyForm Perimeter License 1.0.1. The license permits use, modification, and redistribution, but does not permit using the software to provide a competing product. Review the license terms before adopting or redistributing the project.

Licenses for packages embedded in the distributed bundles are reproduced in THIRD_PARTY_NOTICES.md.

Copyright (c) 2026 Rares (rarepops).

About

GitHub-native CODEOWNERS validation: authoritative diagnostics, duplicate and dangling rules, and unowned tracked files. Node 24 Action and CLI.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

CODEOWNERS Guard

CODEOWNERS Guard

Fast, GitHub-native validation for the CODEOWNERS file that GitHub will actually use.

CICodeQLRelease buildLatest releaseDownloadsLicenseNode.js 24 or newerGitHub Action runtime: Node.js 24Platforms: Windows, Linux, and macOS

Last commit on mainOpen issues

CODEOWNERS Guard combines GitHub's own diagnostics with local repository checks. It runs as a native Node.js action, so it works on Linux, macOS, and Windows without pulling a container image.

Why Guard

  • GitHub is the syntax authority. Diagnostics come from the same CODEOWNERS API that evaluates the selected branch, tag, or commit.
  • Local checks cover the gaps. Duplicate patterns, rules that match no tracked file, and files without an effective owner are reported separately.
  • Action-first feedback. Findings become file annotations and a job summary, with counts exposed as workflow outputs.
  • No container startup. The Action runs directly on Node.js 24 on Linux, macOS, and Windows runners.
  • Useful outside Actions. The same core ships as a cross-platform CLI with deterministic text and JSON output.

Checks

CheckWhat it reportsSeverity
syntaxErrors returned by GitHub's CODEOWNERS API for the selected refError
duplicatesA pattern that appears more than onceWarning
danglingA pattern that matches no tracked fileWarning
unownedA tracked file with no effective owner, including files cleared by an ownerless ruleWarning

Rules use GitHub's last-match-wins behavior. CODEOWNERS Guard searches the standard locations in GitHub's order: .github/CODEOWNERS, CODEOWNERS, then docs/CODEOWNERS.

When the syntax check is disabled, local checks assume the remaining CODEOWNERS lines are valid. Keep syntax enabled in the Action, or validate the committed ref with GitHub before relying on local-only coverage results.

See the check reference for exact matching, exclusion, and result-limit behavior.

GitHub Action

name: CODEOWNERSon:
pull_request:
push:
branches: [main]permissions:
contents: readjobs:
validate:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: rarepops/codeowners-guard@v0.1.1with:
checks: syntax,duplicates,dangling,unownedexclude: | dist/ coverage/

For the strongest supply-chain pinning, replace v0.1.1 with its full commit SHA. A complete least-privilege workflow is available in examples/codeowners.yml.

Released tags are exercised from the independent public integration repository.

The action adds file annotations and a job summary. Its default token is ${{ github.token }}, and the workflow only needs contents: read.

The Action takes its API endpoint from GitHub's runner environment. It does not accept an endpoint input that could redirect the automatically supplied token. GitHub Enterprise Server runners provide their own trusted GITHUB_API_URL.

Inputs

InputDefaultDescription
github-token${{ github.token }}Token used for GitHub diagnostics
path.Repository path relative to GITHUB_WORKSPACE
codeownersauto-detectExplicit CODEOWNERS path
checksall checksComma-separated checks
excludenoneNewline-separated gitignore patterns omitted from local checks
repository${{ github.repository }}Repository in owner/name form
ref${{ github.sha }}Branch, tag, or commit used by the syntax check
fail-onwarningFailure threshold: warning or error
max-annotations50Maximum workflow annotations and summary rows, up to 100

Annotation limits do not change validation counts or failure behavior.

Outputs

The action returns valid, issue-count, error-count, and warning-count.

CLI

Run the published CLI without installing it globally:

npx --yes codeowners-guard@0.1.1 . --checks duplicates,dangling,unowned

Use codeowners-guard@latest instead when you explicitly want the newest release. Pinning a version keeps local and CI runs reproducible.

Build and run the CLI locally:

npm ci
npm run build
node dist/cli.js .

Local checks require no network access:

node dist/cli.js . \
--checks duplicates,dangling,unowned \
--exclude dist/ \
--format json

GitHub's syntax check validates a committed branch, tag, or SHA:

GITHUB_TOKEN=ghp_example node dist/cli.js . \
--checks syntax,duplicates,dangling,unowned \
--repository owner/repository \
--ref main

Tokens are accepted only through GITHUB_TOKEN or GH_TOKEN; command-line token arguments are deliberately unsupported so credentials do not enter shell history or process listings.

Use --max-issues to retain up to 10,000 issue details in text or JSON output. The default is 1,000. Use --fail-on error to report local warnings without returning a failing exit status. Exit code 1 means validation failed, and exit code 2 means the command could not run.

See troubleshooting for authentication, ref mismatch, missing file, and exit-code guidance.

Design

GitHub remains the authority for syntax diagnostics. Local checks operate on files returned by git ls-files, use a maintained gitignore-compatible matcher, and do not make separate user or team lookup calls. This keeps the Action small and avoids maintaining a second copy of GitHub's owner-resolution behavior.

The syntax check targets ref, while local checks target the checked-out working tree. In normal Actions usage both refer to the same commit. For uncommitted local changes, run local checks only or push the change to a ref before requesting GitHub diagnostics.

Security

  • GitHub workflow dependencies are pinned to immutable commit SHAs, and repository settings require SHA-pinned Actions.
  • API calls require HTTPS, reject redirects, time out after 15 seconds, cap responses at 1 MiB, and retry only bounded transient failures.
  • Action paths and CODEOWNERS files cannot escape the checked-out workspace through traversal or symbolic links.
  • Terminal text, workflow annotations, and HTML summaries escape control and bidirectional characters.
  • Dependency installation disables lifecycle scripts; CI checks advisories, registry signatures, and dependency diffs.
  • Tagged release artifacts include SHA-256 checksums and GitHub build-provenance attestations.

Performance

  • Tracked paths stream from git ls-files -z, avoiding a fixed child-process output buffer.
  • GitHub diagnostics and tracked-file enumeration run concurrently.
  • Each file is normalized once and evaluated against ownership rules in one pass, while duplicate-only checks skip Git entirely.
  • Finding details are retained within configured bounds while exact counts and failure behavior cover every finding.
  • npm run bench measures a 10,000-rule duplicate workload and a 10,000-file by 100-rule ownership workload.

Development

Requires Node.js 24 or newer.

npm ci
npm run check
npm run bench

npm run check includes linting, strict type checking, tests with coverage thresholds, and a production build. dist/ is committed because GitHub executes JavaScript actions directly from the repository. CI rejects source changes that do not include rebuilt bundles and third-party notices.

License

CODEOWNERS Guard is source-available under the PolyForm Perimeter License 1.0.1. The license permits use, modification, and redistribution, but does not permit using the software to provide a competing product. Review the license terms before adopting or redistributing the project.

Licenses for packages embedded in the distributed bundles are reproduced in THIRD_PARTY_NOTICES.md.

Copyright (c) 2026 Rares (rarepops).

About

GitHub-native CODEOWNERS validation: authoritative diagnostics, duplicate and dangling rules, and unowned tracked files. Node 24 Action and CLI.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

CODEOWNERS Guard

CODEOWNERS Guard

Fast, GitHub-native validation for the CODEOWNERS file that GitHub will actually use.

CICodeQLRelease buildLatest releaseDownloadsLicenseNode.js 24 or newerGitHub Action runtime: Node.js 24Platforms: Windows, Linux, and macOS

Last commit on mainOpen issues

CODEOWNERS Guard combines GitHub's own diagnostics with local repository checks. It runs as a native Node.js action, so it works on Linux, macOS, and Windows without pulling a container image.

Why Guard

  • GitHub is the syntax authority. Diagnostics come from the same CODEOWNERS API that evaluates the selected branch, tag, or commit.
  • Local checks cover the gaps. Duplicate patterns, rules that match no tracked file, and files without an effective owner are reported separately.
  • Action-first feedback. Findings become file annotations and a job summary, with counts exposed as workflow outputs.
  • No container startup. The Action runs directly on Node.js 24 on Linux, macOS, and Windows runners.
  • Useful outside Actions. The same core ships as a cross-platform CLI with deterministic text and JSON output.

Checks

CheckWhat it reportsSeverity
syntaxErrors returned by GitHub's CODEOWNERS API for the selected refError
duplicatesA pattern that appears more than onceWarning
danglingA pattern that matches no tracked fileWarning
unownedA tracked file with no effective owner, including files cleared by an ownerless ruleWarning

Rules use GitHub's last-match-wins behavior. CODEOWNERS Guard searches the standard locations in GitHub's order: .github/CODEOWNERS, CODEOWNERS, then docs/CODEOWNERS.

When the syntax check is disabled, local checks assume the remaining CODEOWNERS lines are valid. Keep syntax enabled in the Action, or validate the committed ref with GitHub before relying on local-only coverage results.

See the check reference for exact matching, exclusion, and result-limit behavior.

GitHub Action

name: CODEOWNERSon:
pull_request:
push:
branches: [main]permissions:
contents: readjobs:
validate:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: rarepops/codeowners-guard@v0.1.1with:
checks: syntax,duplicates,dangling,unownedexclude: | dist/ coverage/

For the strongest supply-chain pinning, replace v0.1.1 with its full commit SHA. A complete least-privilege workflow is available in examples/codeowners.yml.

Released tags are exercised from the independent public integration repository.

The action adds file annotations and a job summary. Its default token is ${{ github.token }}, and the workflow only needs contents: read.

The Action takes its API endpoint from GitHub's runner environment. It does not accept an endpoint input that could redirect the automatically supplied token. GitHub Enterprise Server runners provide their own trusted GITHUB_API_URL.

Inputs

InputDefaultDescription
github-token${{ github.token }}Token used for GitHub diagnostics
path.Repository path relative to GITHUB_WORKSPACE
codeownersauto-detectExplicit CODEOWNERS path
checksall checksComma-separated checks
excludenoneNewline-separated gitignore patterns omitted from local checks
repository${{ github.repository }}Repository in owner/name form
ref${{ github.sha }}Branch, tag, or commit used by the syntax check
fail-onwarningFailure threshold: warning or error
max-annotations50Maximum workflow annotations and summary rows, up to 100

Annotation limits do not change validation counts or failure behavior.

Outputs

The action returns valid, issue-count, error-count, and warning-count.

CLI

Run the published CLI without installing it globally:

npx --yes codeowners-guard@0.1.1 . --checks duplicates,dangling,unowned

Use codeowners-guard@latest instead when you explicitly want the newest release. Pinning a version keeps local and CI runs reproducible.

Build and run the CLI locally:

npm ci
npm run build
node dist/cli.js .

Local checks require no network access:

node dist/cli.js . \
--checks duplicates,dangling,unowned \
--exclude dist/ \
--format json

GitHub's syntax check validates a committed branch, tag, or SHA:

GITHUB_TOKEN=ghp_example node dist/cli.js . \
--checks syntax,duplicates,dangling,unowned \
--repository owner/repository \
--ref main

Tokens are accepted only through GITHUB_TOKEN or GH_TOKEN; command-line token arguments are deliberately unsupported so credentials do not enter shell history or process listings.

Use --max-issues to retain up to 10,000 issue details in text or JSON output. The default is 1,000. Use --fail-on error to report local warnings without returning a failing exit status. Exit code 1 means validation failed, and exit code 2 means the command could not run.

See troubleshooting for authentication, ref mismatch, missing file, and exit-code guidance.

Design

GitHub remains the authority for syntax diagnostics. Local checks operate on files returned by git ls-files, use a maintained gitignore-compatible matcher, and do not make separate user or team lookup calls. This keeps the Action small and avoids maintaining a second copy of GitHub's owner-resolution behavior.

The syntax check targets ref, while local checks target the checked-out working tree. In normal Actions usage both refer to the same commit. For uncommitted local changes, run local checks only or push the change to a ref before requesting GitHub diagnostics.

Security

  • GitHub workflow dependencies are pinned to immutable commit SHAs, and repository settings require SHA-pinned Actions.
  • API calls require HTTPS, reject redirects, time out after 15 seconds, cap responses at 1 MiB, and retry only bounded transient failures.
  • Action paths and CODEOWNERS files cannot escape the checked-out workspace through traversal or symbolic links.
  • Terminal text, workflow annotations, and HTML summaries escape control and bidirectional characters.
  • Dependency installation disables lifecycle scripts; CI checks advisories, registry signatures, and dependency diffs.
  • Tagged release artifacts include SHA-256 checksums and GitHub build-provenance attestations.

Performance

  • Tracked paths stream from git ls-files -z, avoiding a fixed child-process output buffer.
  • GitHub diagnostics and tracked-file enumeration run concurrently.
  • Each file is normalized once and evaluated against ownership rules in one pass, while duplicate-only checks skip Git entirely.
  • Finding details are retained within configured bounds while exact counts and failure behavior cover every finding.
  • npm run bench measures a 10,000-rule duplicate workload and a 10,000-file by 100-rule ownership workload.

Development

Requires Node.js 24 or newer.

npm ci
npm run check
npm run bench

npm run check includes linting, strict type checking, tests with coverage thresholds, and a production build. dist/ is committed because GitHub executes JavaScript actions directly from the repository. CI rejects source changes that do not include rebuilt bundles and third-party notices.

License

CODEOWNERS Guard is source-available under the PolyForm Perimeter License 1.0.1. The license permits use, modification, and redistribution, but does not permit using the software to provide a competing product. Review the license terms before adopting or redistributing the project.

Licenses for packages embedded in the distributed bundles are reproduced in THIRD_PARTY_NOTICES.md.

Copyright (c) 2026 Rares (rarepops).

About

GitHub-native CODEOWNERS validation: authoritative diagnostics, duplicate and dangling rules, and unowned tracked files. Node 24 Action and CLI.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages