Skip to main content

CheckOwners

CI codecov PyPI PyPI downloads Python versions License: MIT

Infer CODEOWNERS from git history with confidence scoring, a knowledge graph, expertise decay detection, team topology inference, review load balancing, and onboarding paths. Core inference is deterministic git analysis; no LLM is in that path. CI-native: structured JSON output, GITHUB_OUTPUT integration, composite GitHub Action.

This repository moved here from a previous GitHub organization; Sigstore attestations for 0.5.0 and earlier record that earlier publisher. 0.5.1 and later are published from smusali/checkowners.

CheckOwners treats code ownership as a confidence-scored spectrum rather than a static binary declaration.

No other open-source tool combines git-history inference, calibrated per-path confidence, pattern-aware drift with severity tiers, and knowledge-risk reporting behind a single CI-native JSON contract.

Inference is deterministic git analysis; the scoring heuristics live in analyze.py and are auditable. The codebase has been built with agent assistance. Every AI-assisted change is human-reviewed, tested, and signed off.

See it

analyze → generate → drift on this repository:

checkowners analyze, generate, and drift

The composite Action keeps one comment on same-repo pull requests. When drift clears it looks like this (from the dogfood workflow on this repo):

CheckOwners pull-request comment

Trimmed JSON for the same run is in examples/sample-output.md. Reference configs live under examples/.

How it works

checkowners analyze reads git log and git blame (in parallel, only over paths that can actually produce owners; a 24k-commit, 12k-file production monorepo completed a 365-day analyze in under three minutes on the 0.5.0 dogfood run) into a confidence-scored ownership map cached per repo under ~/.checkowners/. Commit emails resolve to GitHub @handles (noreply emails locally with no token, the rest via the GitHub API), and same-person identities merge so qualified owner counts count people, not email addresses. From that map, generate writes a CODEOWNERS file with uniform directories consolidated into dir/ rules, and drift compares the committed file against inference using real CODEOWNERS pattern matching (directory rules, globs, last-match-wins). qualified-owners, decay, topology, balance, onboard, and trends emit their own reports. In CI, the composite GitHub Action runs the same flow, writes structured GITHUB_OUTPUT and a job summary, and maintains a single up-to-date PR comment on same-repo pull requests. See docs/USAGE.md for the full pipeline and a diagram.

Installation

Requires Python 3.11 through 3.14.

pip install checkowners               # core CLI (pure git, zero API deps)
pip install "checkowners[graph]"      # + networkx-backed graph / topology / onboard
pip install "checkowners[github]"     # + GitHub API handle/team/review resolution
pip install "checkowners[all]"        # everything

Quick start

# Confidence-scored ownership inference
checkowners analyze

# Write CODEOWNERS with owners ranked by expertise confidence
# (refuses to overwrite a hand-written file unless you pass --force)
checkowners generate

# Compare inferred vs current CODEOWNERS, ranked by confidence delta
checkowners drift

# Validate syntax (no git access)
checkowners validate

All commands accept --json (except graph, which exports DOT via --export dot) and persist their results per repo under ~/.checkowners/ so downstream commands can reuse the analysis.

Commands

Command What it does
checkowners analyze Infer ownership with confidence scores, qualified owner count, decay warnings
checkowners generate Write CODEOWNERS, ordered by confidence; optional inline annotations
checkowners print Print inferred ownership to stdout
checkowners validate Validate existing CODEOWNERS syntax
checkowners drift Compare inferred vs current; severity + max confidence delta
checkowners notify POST drift to a webhook gated by severity_threshold
checkowners sync Generate CODEOWNERS and commit the result
checkowners expertise <path> Per-path expertise ranking
checkowners decay Detect dormant owners; recommend transfers
checkowners graph [--export dot] Render the contributor / file / team graph
checkowners qualified-owners [<path>] [--all] Per-path qualified owner count (capped by top_n_owners) with backup-reviewer suggestions. bus-factor is a deprecated alias pending redefinition
checkowners topology Infer team boundaries from commit co-occurrence
checkowners balance Detect overloaded reviewers and propose rebalancing
checkowners onboard <path> Generate a learning path from broad-ownership to deep-expertise files
checkowners trends [--periods N] [--period-days D] Show how ownership confidence and qualified owner count have evolved over time
checkowners github-action Run the full CI flow and write GITHUB_OUTPUT; used by the composite Action

Documentation

License

MIT

Metadata

Release files for checkowners 0.5.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for checkowners 0.5.1
File Size Uploaded
checkowners-0.5.1.tar.gz 243.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for checkowners 0.5.1
File Interpreter ABI Platform
checkowners-0.5.1-py3-none-any.whl Python 3 none any Details

Total release size: 300.6 kB

Release files / checkowners-0.5.1.tar.gz

Download URL checkowners-0.5.1.tar.gz
Size 243.9 kB
Tags Source
SHA-256 checksum
How to use checksums
9dff1f17b94b7f8df1eecf3505e3bc22bdeb11e5075dc841cb0f27f866660720
BLAKE2b-256 checksum
How to use checksums
d00464b60538b61f698d57889dd149ca0f00525b09819c2e10f81d9f5f4f18a8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.

Transparency log

Release files / checkowners-0.5.1-py3-none-any.whl

Download URL checkowners-0.5.1-py3-none-any.whl
Size 56.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
380fecff6b1cfb900f05bab3819c28ae3a6d97ff8b07ddba4684116abe37a0f6
BLAKE2b-256 checksum
How to use checksums
a6cd3c8f2e866e1bd37cbd9c1401213dde3234c01bacbdeba6589a853508d1d5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.

Transparency log

Release history Release notifications | RSS feed

0.6.0

2 release files

This release

0.5.1 This release

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page