Both job types above come from the GitHub 29 Branch Source plugin (1983.vfa_27ed961853 here, maintained mainly by CloudBees 21,188 ). It talks to GitHub's REST API with the configured credential, turns branches, pull requests and tags into SCM heads, fetches the Jenkinsfile of each head through the API without cloning, and reports results back (Commit Status Checks). Its behavior is a list of traits:
| Trait | Setting used for BookNest | Effect |
|---|---|---|
| Discover branches | Exclude branches also filed as PRs | Each change builds once |
| Discover pull requests from origin | Merge with target | Tests the post-merge result |
| Discover pull requests from forks | Merge; trust users with write access | Untrusted forks cannot change the Jenkinsfile |
| Filter by name (regex) | booknest-jenkins.* (folder only) | Limits which repositories are scanned |
The fork rule matters: an untrusted fork's pull request is built with the target branch's Jenkinsfile, so a stranger cannot submit one that prints your credentials. A fine-grained token works, but the project recommends a GitHub App: its installation tokens are short lived, its API limit can grow beyond a user's 5,000 requests an hour, and it is the only way to publish GitHub checks. Creating an App requires the owner's browser sign-in, so it is not run here.