GitHub Branch Source

The GitHub Branch Source Plugin

Both job types above come from the GitHub 29 Branch Source plugin (1983.vfa_27ed961853 here, maintained mainly by CloudBees 21,188 ). It talks to GitHub's REST API with the configured credential, turns branches, pull requests and tags into SCM heads, fetches the Jenkinsfile of each head through the API without cloning, and reports results back (Commit Status Checks). Its behavior is a list of traits:

GitHub Branch Source traits in the BookNest jobs
Trait Setting used for BookNest Effect
Discover branches Exclude branches also filed as PRs Each change builds once
Discover pull requests from origin Merge with target Tests the post-merge result
Discover pull requests from forks Merge; trust users with write access Untrusted forks cannot change the Jenkinsfile
Filter by name (regex) booknest-jenkins.* (folder only) Limits which repositories are scanned

The fork rule matters: an untrusted fork's pull request is built with the target branch's Jenkinsfile, so a stranger cannot submit one that prints your credentials. A fine-grained token works, but the project recommends a GitHub App: its installation tokens are short lived, its API limit can grow beyond a user's 5,000 requests an hour, and it is the only way to publish GitHub checks. Creating an App requires the owner's browser sign-in, so it is not run here.