Securing CI/CD for an open source project: Controlling who runs what
… For CI configuration that means anything under .github/ is owned by @cilium/github-sec our security-focused CI team plus @cilium/ci-structure, and the auto-approve.yaml workflow is owned by @cilium/cilium-maintainers: CODEOWNERS /.github/ @cilium/github-sec @cilium/ci-structure /.github/ariane-conf… …