如何避免从dev分支向master分支发起PR时CODEOWNERS文件被覆盖?
Great question—this is a common pitfall when using branch-specific CODEOWNERS setups. Let’s walk through practical, team-friendly solutions to keep your master branch’s DevOps team requirement intact while still having dev branch-specific reviewers.
Approach 1: Use Git’s ours Merge Strategy (My Go-To Fix)
This is a Git-native solution that automatically preserves the master branch’s CODEOWNERS file during merges. Here’s how to set it up:
- Switch to your
masterbranch locally. - Create (or edit) a
.gitattributesfile in your repo’s root directory. - Add this line to the file:
CODEOWNERS merge=ours - Commit and push this
.gitattributesfile tomaster.
From now on, whenever you merge dev into master, Git will automatically keep the master version of CODEOWNERS and ignore the one from dev. No manual conflict resolution needed, and it works quietly in the background for your team.
Approach 2: Replace dev’s CODEOWNERS with Branch Protection Rules
If you only use the dev branch’s CODEOWNERS to set default reviewers, you can ditch the file entirely and use platform-specific branch protection instead:
- For GitHub: Head to your repo’s Settings > Branches > Branch protection rules, create a rule for
dev, and under "Require pull request reviews before merging", add your dev team as mandatory reviewers. - For GitLab: Go to Settings > Repository > Protected branches, select
dev, and configure your dev team as required reviewers in the merge request settings.
This eliminates the risk of overwriting master’s CODEOWNERS entirely, while still enforcing your dev branch review requirements.
Approach 3: Block CODEOWNERS Edits in PRs to master via CI/CD
If you want to keep the CODEOWNERS file in dev but prevent it from ever being merged into master, add a CI check to block such changes:
- In GitHub Actions, GitLab CI, or your tool of choice, create a workflow that runs on pull requests targeting
master. - The workflow checks if the
CODEOWNERSfile has been modified. If it has, the check fails and blocks the merge.
Here’s a quick GitHub Actions example:
jobs: block-codeowners-changes: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 with: fetch-depth: 0 - name: Check for CODEOWNERS modifications run: | if git diff origin/master HEAD --name-only | grep -q "^CODEOWNERS$"; then echo "❌ ERROR: CODEOWNERS changes are not allowed in PRs to master!" exit 1 fi
This gives your team clear feedback if someone accidentally tries to merge the dev CODEOWNERS into master.
Approach 4: Restrict CODEOWNERS Edits to DevOps Only
Add a branch protection rule for master that limits who can modify the CODEOWNERS file:
- In GitHub: Under the master branch protection rule, enable "Restrict who can push to matching branches" and add only the DevOps team as allowed pushers.
- In GitLab: Set up a protected branch rule for
masterthat restricts "Allowed to push" to the DevOps team.
This way, even if someone tries to merge a CODEOWNERS change from dev, the branch protection will block it unless the DevOps team explicitly approves the edit.
内容的提问来源于stack exchange,提问作者Vlad

