Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Actions: keep workflow runs safe | 1 | -- Workflow jobs' tokens (G1T_TOKEN, and GITHUB_TOKEN as its alias): each |
| 2 | -- belongs to the repository's workspace, reaches one repository only, and | |
| 3 | -- carries the scopes the job's `permissions:` give it. The actions service | |
| 4 | -- revokes a job's tokens when the job ends. See src/job_tokens.rs. | |
| 5 | -- | |
| 6 | -- `repo` is `owner/name`: a token with one is refused everywhere else. | |
| 7 | -- `job_id` and `job_run_id` name the job and its run, which the audit log | |
| 8 | -- records against what the token does. All three are null on every other | |
| 9 | -- token, so nothing existing changes. | |
| 10 | ALTER TABLE access_tokens ADD COLUMN repo TEXT; | |
| 11 | ALTER TABLE access_tokens ADD COLUMN job_id TEXT; | |
| 12 | ALTER TABLE access_tokens ADD COLUMN job_run_id TEXT; | |
| Merge main into the run-protection branch | 13 | -- 1 when the job may open and approve pull requests (its repository and |
| 14 | -- workspace allow it); 0 or null otherwise. | |
| 15 | ALTER TABLE access_tokens ADD COLUMN job_pulls INTEGER; | |
| Actions: keep workflow runs safe | 16 | CREATE INDEX access_tokens_job ON access_tokens (job_id) WHERE job_id IS NOT NULL; |
This file's history is long; its oldest lines are credited to the oldest commit read.