GitHub 29 Branch Source reports every build back to the commit, so a pull request shows Jenkins 8,793 ' result next to GitHub's merge button. With a token or password credential it uses the commit status API (contexts such as continuous-integration/jenkins/pr-merge); with a GitHub App credential, the GitHub Checks plugin installed in Plugin Manager publishes richer check runs instead. This fine-grained token lacks the Commit statuses: write permission, and the builds show what happens then:
J=http://localhost:32080
curl -s -u "admin:$JENKINS_TOKEN" $J/job/booknest/job/main/lastBuild/consoleText \
| grep -m1 'Could not update commit status' | cut -c1-95
gh api repos/binarybehemoth/booknest-jenkins/commits/main/status --jq '{state, total_count}'Could not update commit status. Message: {"message":"Resource not accessible by personal access
{"state":"pending","total_count":0}The report failed with HTTP 403 at the start and end of every build, yet the builds succeeded: a failed notification never fails a build, so it is easy to miss. GitHub shows pending with zero statuses, and a branch rule requiring a Jenkins status could never pass. The fixes are to give the token Commit statuses: read and write, or to switch to a GitHub App with Checks and Commit statuses write access, which adds check runs with stage details. Both change the account's settings and are not run here.