pub fn render_workflow(
cfg: &VgiConfig,
checkout_action: &str,
repo: &Resource,
) -> StringExpand description
The workflow committed to the repository (outside a required-workflow
namespace). Differs from the dormant one in the runbook: there is no
if: vars.TRUST_REGISTRY_DID != '' guard (a skipped required job
counts as passing), and the DIDs are literals rather than vars.*,
which any repository admin could change.
The namespace is the fallback resource (fallback_resource): the VTC
publishes namespace-wide commit rights — a git.ns.admin’s implied
git.commit.sign, the bridge’s service grant — on it, not on each
repository.