deckhearth/.github/CODEOWNERS
Randall Stillwell 1944b1ed48 bootstrap: agent pipeline v0.5.0 + ship-readiness review
Installs the three-layer agent-pipeline scaffold (https://github.com/varutasu/agent-pipeline @ v0.5.0):

L1 — Context (curated brain)
- AGENTS.md: orientation, conventions, 8 explicit gotchas
- .cursor/rules/: no-go-zones, api-routes, auth-and-permissions,
  db-and-schema, ui-and-theming, schema-map
- .cursor/skills/: add-api-route, add-page recipes
- docs/agent-context/README.md: layer explainer
- docs/SCHEMA_MAP.md: hand-curated Neon Postgres reference
  (replaces Prisma schema map since stack is raw SQL)

L2 — Subagent roles (copied verbatim from upstream templates)
- 9 .cursor/agents/role-*.md files: Conductor, IA-Architect,
  UX-Reviewer, Architect, Implementer, Reviewer,
  Design-System-Auditor, A11y-Auditor, Doc-Writer

L3 — Pipeline scaffolding (Vercel variant)
- CI: lint + schema-map-drift only (no duplicate build —
  Vercel handles it). Test job commented out until vitest lands.
- preview-smoke + visual-diff via wait-for-vercel-preview
- pr-health-rollup sticky comment aggregator
- agent-context-drift weekly cron
- PULL_REQUEST_TEMPLATE, CODEOWNERS (auth/admin paths tagged)
- .convoys/ folder + seed ship-readiness.md review
- lib/flags/index.js (JS — converted from TS template)
- scripts/wt.sh (Cursor 3.2 deprecation stub),
  scripts/log-convoy-event.sh
- tests/smoke/app.smoke.spec.ts (Playwright skeleton)

Manifest
- .agent-context-manifest.yml: tracks 31 artifacts by sha256
  for future sync-agent-context drift detection

Review
- .convoys/ship-readiness.md: 16 findings (7 P0 ship-blockers,
  5 P1 quality-bar, 4 P2 refactor, P3 UX/IA/a11y/docs) with
  proposed 13-convoy launch sequence.

No production code changed in this commit. All findings in
the ship-readiness review will be addressed in follow-up convoys
starting with fix-auth-bypass.

Structural brain: user-code-review-graph MCP has indexed the
codebase (122 files, 628 nodes, 5602 edges, 11 communities,
84 flows). Per-developer; not committed.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-23 02:31:26 -05:00

43 lines
2.1 KiB
Text

# CODEOWNERS — review routing for the agent pipeline.
# Replace @YOUR-GITHUB-HANDLE with the project owner's GitHub handle.
# Global default
* @YOUR-GITHUB-HANDLE
# High-risk: auth — every change here needs a maintainer review
pages/api/auth/** @YOUR-GITHUB-HANDLE
pages/api/auth-utils.js @YOUR-GITHUB-HANDLE
lib/permission-middleware.js @YOUR-GITHUB-HANDLE
lib/auth-context.js @YOUR-GITHUB-HANDLE
lib/admin-auth.js @YOUR-GITHUB-HANDLE
lib/use-auth.js @YOUR-GITHUB-HANDLE
components/ProtectedRoute.js @YOUR-GITHUB-HANDLE
components/AdminProtected.js @YOUR-GITHUB-HANDLE
# High-risk: admin operations + DB setup
pages/api/admin/** @YOUR-GITHUB-HANDLE
pages/api/setup-database.js @YOUR-GITHUB-HANDLE
scripts/setup-neon-db.js @YOUR-GITHUB-HANDLE
scripts/reset-db.js @YOUR-GITHUB-HANDLE
scripts/promote-user-to-admin.js @YOUR-GITHUB-HANDLE
scripts/demote-admin-to-user.js @YOUR-GITHUB-HANDLE
# Schema changes need extra eyes (until a real migration tool is adopted)
scripts/add-*.js @YOUR-GITHUB-HANDLE
scripts/fix-*.js @YOUR-GITHUB-HANDLE
docs/SCHEMA_MAP.md @YOUR-GITHUB-HANDLE
# Feature flags
lib/flags/** @YOUR-GITHUB-HANDLE
# CI / infra
.github/workflows/** @YOUR-GITHUB-HANDLE
next.config.js @YOUR-GITHUB-HANDLE
vercel.json @YOUR-GITHUB-HANDLE
# Agent context
.cursor/agents/** @YOUR-GITHUB-HANDLE
.cursor/rules/** @YOUR-GITHUB-HANDLE
.cursor/skills/** @YOUR-GITHUB-HANDLE
AGENTS.md @YOUR-GITHUB-HANDLE
.agent-context-manifest.yml @YOUR-GITHUB-HANDLE