Skip to main content

Governance

Your .fossid/ folder holds decisions with compliance consequences:

  • the license policy and detection rules (policy.json);
  • custom volumes;
  • accepted exceptions (ignores.yaml).

On GitHub, you can require that every change to these files is reviewed by your compliance or open source program office (OSPO) team.

Set Up .fossid/ Governance​

  1. Run FossID: Set Up .fossid/ Governance from the Command Palette.
  2. Enter the owner who must review changes: a GitHub user (@username), a team (@org/compliance) or an email address. Only one owner is accepted.

FossID adds this rule to your repository's CODEOWNERS file:

# FossID compliance files — changes route to the owner below for required review.
.fossid/** @org/compliance

It uses the first CODEOWNERS file it finds: .github/CODEOWNERS, then CODEOWNERS, then docs/CODEOWNERS. If there isn't one, it creates .github/CODEOWNERS. If a .fossid/** rule already exists, it is updated. Nothing else in the file changes, and running the command again is safe.

Commit and push the CODEOWNERS change as usual.

Enforce the review​

A CODEOWNERS entry only requests a review. To require it, turn on branch protection. Select Branch-protection step in FossID's confirmation for instructions. For a GitHub repository, Open branch protection settings takes you straight there. On your default branch, enable:

  • Require a pull request before merging;
  • Require review from Code Owners.

This step is described for GitHub. On other hosting platforms, use their equivalent code-owner review setting.