Skip to main content

fallback_resource

Function fallback_resource 

Source
pub fn fallback_resource(repo: &Resource) -> String
Expand description

The fallback-resource value both workflows pass: <forge-host>/${{ github.repository_owner }}.

The VTC publishes a namespace’s commit rights — every git.ns.admin’s implied git.commit.sign, a namespace-wide grant, the bridge’s service grant that its re-signed Dependabot commits rely on — on the namespace resource (github.com/acme), and a bridge that sets up a repository’s check must make the namespace its fallback (git-ns right/grant 0.1).

Exactly the repository’s own namespace, never broader:

  • the owner is the one GitHub runs the job for, read at run time, so one file serves every repository of an organisation (the required workflow) and a copy in another owner’s repository names that owner, never this one;
  • the host is the forge’s, fixed here (a resource names no scheme, so github.server_url cannot be used as is);
  • the value reaches verify-trust through the action’s environment, never a script, and verify-trust refuses a fallback that does not contain the repository’s own resource (another owner, another forge);
  • it is only ever written next to resource-format: qualified — a legacy run takes no forge-qualified fallback.