pub fn render_required_workflow(
cfg: &VgiConfig,
checkout_action: &str,
repo: &Resource,
keyring: &[u8],
) -> Result<String>Expand description
The required workflow held in <org>/.vgi. It runs in the context of
the repository under test (its GITHUB_REPOSITORY, its pull request),
but everything that decides how to check is fixed here, at the pinned
commit:
- the DIDs are literals, not
vars.*— a repository variable overrides an organisation one of the same name, and repository admins set those; - the exempt keyring is written from this file to the runner’s temp directory, not read from the repository, where the pull request could add its own key to it.
It is shared by every managed repository of the organisation, so the
fallback resource names the namespace of the repository it runs for, read
at run time (fallback_resource) rather than written in.