Governance
Your .fossid/ folder holds decisions with compliance consequences:
- the license policy and detection rules (
policy.json); - custom volumes;
- accepted exceptions (
ignores.yaml).
On GitHub, you can require that every change to these files is reviewed by your compliance or open source program office (OSPO) team.
Set Up .fossid/ Governance
- Run FossID: Set Up .fossid/ Governance from the Command Palette.
- Enter the owner who must review changes: a GitHub user (
@username), a team (@org/compliance) or an email address. Only one owner is accepted.
FossID adds this rule to your repository's CODEOWNERS file:
# FossID compliance files — changes route to the owner below for required review.
.fossid/** @org/compliance
It uses the first CODEOWNERS file it finds: .github/CODEOWNERS, then CODEOWNERS, then docs/CODEOWNERS. If there isn't one, it creates .github/CODEOWNERS. If a .fossid/** rule already exists, it is updated. Nothing else in the file changes, and running the command again is safe.
Commit and push the CODEOWNERS change as usual.
Enforce the review
A CODEOWNERS entry only requests a review. To require it, turn on branch protection. Select Branch-protection step in FossID's confirmation for instructions. For a GitHub repository, Open branch protection settings takes you straight there. On your default branch, enable:
- Require a pull request before merging;
- Require review from Code Owners.
This step is described for GitHub. On other hosting platforms, use their equivalent code-owner review setting.