Secrets and variables: one list, rows per environment, for workflows and deployments
Shaped like Vercel's environment variables, after looking at how GitHub, GitLab, Vercel, Netlify, Railway, Cloudflare, CircleCI and Doppler split the same question. Each row is a key, its type (Secret, or Config, which can become a secret but never back), a note, the environments it applies to (all, or production, preview, or a workflow job's `environment:`) and who reads it: Workflows, Deployments, or both. A key can hold a row per environment, so production gets the live key and previews the test one. A workspace's rows reach every repository or the ones linked; a repository's row of the same key wins. - Actions service: migration 0003 rebuilds `settings` as rows (no unique key; a key's rows of one type never overlap); `resolve_settings` for the deployments service. A reader gets each key's row for its environment, else the row for all. Untrusted runs (pull requests from outside the workspace) get no secrets. Workflow jobs read the row for their `environment:`. - G1T_TOKEN: every trusted job gets the workspace's own token as `secrets.G1T_TOKEN`, with `GITHUB_TOKEN` (and `github.token`) as its alias. Keys starting with G1T_ or GITHUB_ are g1t's own. - Workspace tokens, G1T_TOKEN included, can no longer change secrets and variables; before, a trusted workflow's token could rewrite a repository's. - Deployments: builds get the rows available to Deployments as their environment (secrets hidden in the log); the running app gets them as bindings, put in place by g1t, never through the build's sandbox. "Build variables" on the Deployments page are gone. - API and MCP: GitHub's routes unchanged, with `id`, `environments`, `availableTo`, `repositories` and `note` added. - Site: one list with search and type and environment filters; Add and Edit in a side panel with Secret/Config cards; pasting a .env file adds many. Deployment settings move to Settings → Deployments. Settings are tidied: one icon per thing (a lock for secrets, a key for tokens), "Members" everywhere, "Billing and plans", workspace settings in one order, breadcrumbs that name a repository's settings page. - Docs: guides/secrets-and-variables (rows, environments, who reads what, who gets secrets, G1T_TOKEN, the API); Actions, Deployments, Workspaces, MCP and llms.txt updated.
No changes