pub fn fallback_resource(repo: &Resource) -> StringExpand description
The fallback-resource value both workflows pass:
<forge-host>/${{ github.repository_owner }}.
The VTC publishes a namespace’s commit rights — every git.ns.admin’s
implied git.commit.sign, a namespace-wide grant, the bridge’s service
grant that its re-signed Dependabot commits rely on — on the namespace
resource (github.com/acme), and a bridge that sets up a repository’s
check must make the namespace its fallback (git-ns right/grant 0.1).
Exactly the repository’s own namespace, never broader:
- the owner is the one GitHub runs the job for, read at run time, so one file serves every repository of an organisation (the required workflow) and a copy in another owner’s repository names that owner, never this one;
- the host is the forge’s, fixed here (a resource names no scheme, so
github.server_urlcannot be used as is); - the value reaches verify-trust through the action’s environment, never a script, and verify-trust refuses a fallback that does not contain the repository’s own resource (another owner, another forge);
- it is only ever written next to
resource-format: qualified— a legacy run takes no forge-qualified fallback.