GitHub
Code quality
No CODEOWNERS file
Part of the Release & branch safety check · fix arrives as a pull request
What it is
The repository has no CODEOWNERS file, so no reviewer is automatically requested for changes to sensitive paths.
Why it matters
Review assignment falls to whoever is around. Changes to authentication, payments, or infrastructure can be approved by someone with no context on them, which is exactly where a second pair of eyes was meant to help.
How to fix it
Add CODEOWNERS mapping sensitive directories to the people or teams who own them, and enable required review from code owners in branch protection so the assignment has teeth.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.