PageSourceSearch

https://woodpecker-ci.org/assets/js/f4216412.985bd2c8.js

js woodpecker-ci.org collected 2026-10-04 00:31:23 UTC 8,690 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkwoodpecker=self.webpackChunkwoodpecker||[]).push([["3442"],{60975(e,t,i){i.r(t),i.d(t,{metadata:()=>n,default:()=>p,frontMatter:()=>r,contentTitle:()=>l,toc:()=>c,assets:()=>a});var n=JSON.parse('{"id":"usage/project-settings","title":"Project settings","description":"As the owner of a project in Woodpecker you can change project related settings via the web interface.","source":"@site/versioned_docs/version-3.17/20-usage/75-project-settings.md","sourceDirName":"20-usage","slug":"/usage/project-settings","permalink":"/docs/3.17/usage/project-settings","draft":false,"unlisted":false,"editUrl":"https://github.com/woodpecker-ci/woodpecker/edit/main/docs/versioned_docs/version-3.17/20-usage/75-project-settings.md","tags":[],"version":"3.17","sidebarPosition":75,"frontMatter":{},"sidebar":"tutorialSidebar","previous":{"title":"Local pipeline execution","permalink":"/docs/3.17/usage/local-execution"},"next":{"title":"Status Badges","permalink":"/docs/3.17/usage/badges"}}'),o=i(94686),s=i(23191);let r={},l="Project settings",a={},c=[{value:"Pipeline path",id:"pipeline-path",level:2},{value:"Repository hooks",id:"repository-hooks",level:2},{value:"Allow pull requests",id:"allow-pull-requests",level:2},{value:"Allow deployments",id:"allow-deployments",level:2},{value:"Require approval for",id:"require-approval-for",level:2},{value:"Trusted",id:"trusted",level:2},{value:"Custom trusted clone plugins",id:"custom-trusted-clone-plugins",level:2},{value:"Project visibility",id:"project-visibility",level:2},{value:"Timeout",id:"timeout",level:2},{value:"Cancel previous pipelines",id:"cancel-previous-pipelines",level:2}];function d(e){let t={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",header:"header",img:"img",li:"li",p:"p",ul:"ul",...(0,s.R)(),...e.components};return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(t.header,{children:(0,o.jsx)(t.h1,{id:"project-settings",children:"Project settings"})}),"\n",(0,o.jsx)(t.p,{children:"As the owner of a project in Woodpecker you can change project related settings via the web interface."}),"\n",(0,o.jsx)(t.p,{children:(0,o.jsx)(t.img,{alt:"project settings",src:i(53643).A+"",width:"2044",height:"2619"})}),"\n",(0,o.jsx)(t.admonition,{type:"note",children:(0,o.jsx)(t.p,{children:"Woodpecker's permission handling is linked to the forge. A user on your forge that has admin access to the repo will also get admin permissions for the repository in Woodpecker and can then change the settings here."})}),"\n",(0,o.jsx)(t.h2,{id:"pipeline-path",children:"Pipeline path"}),"\n",(0,o.jsxs)(t.p,{children:["The path to the pipeline config file or folder. By default it is left empty which will use the following configuration resolution ",(0,o.jsx)(t.code,{children:".woodpecker/*.{yaml,yml}"})," -> ",(0,o.jsx)(t.code,{children:".woodpecker.yaml"})," -> ",(0,o.jsx)(t.code,{children:".woodpecker.yml"}),". If you set a custom path Woodpecker tries to load your configuration or fails if no configuration could be found at the specified location. To use a ",(0,o.jsx)(t.a,{href:"/docs/3.17/usage/workflows",children:"multiple workflows"})," with a custom path you have to change it to a folder path ending with a ",(0,o.jsx)(t.code,{children:"/"})," like ",(0,o.jsx)(t.code,{children:".woodpecker/"}),"."]}),"\n",(0,o.jsx)(t.h2,{id:"repository-hooks",children:"Repository hooks"}),"\n",(0,o.jsx)(t.p,{children:"Your Version-Control-System will notify Woodpecker about events via webhooks. If you want your pipeline to only run on specific webhooks, you can check them with this setting."}),"\n",(0,o.jsx)(t.h2,{id:"allow-pull-requests",children:"Allow pull requests"}),"\n",(0,o.jsx)(t.p,{children:"Enables handling webhook's pull request event. If disabled, then pipeline won't run for pull requests."}),"\n",(0,o.jsx)(t.h2,{id:"allow-deployments",children:"Allow deployments"}),"\n",(0,o.jsxs)(t.p,{children:["Enables a pipeline to be started with the ",(0,o.jsx)(t.code,{children:"deploy"})," event from a successful pipeline."]}),"\n",(0,o.jsx)(t.admonition,{type:"danger",children:(0,o.jsxs)(t.p,{children:["Only activate this option if you trust all users who have push access to your repository.\nOtherwise, these users will be able to steal secrets that are only available for ",(0,o.jsx)(t.code,{children:"deploy"})," events."]})}),"\n",(0,o.jsx)(t.h2,{id:"require-approval-for",children:"Require approval for"}),"\n",(0,o.jsxs)(t.p,{children:["To prevent malicious pipelines from extracting secrets or running harmful commands or to prevent accidental pipeline runs, you can require approval for an additional review process. Depending on the enabled o
1ption, a pipeline will be put on hold after creation and will only continue after approval. The default restrictive setting is ",(0,o.jsx)(t.code,{children:"Approvals for forked repositories"}),"."]}),"\n",(0,o.jsx)(t.h2,{id:"trusted",children:"Trusted"}),"\n",(0,o.jsx)(t.p,{children:"If you set your project to trusted, a pipeline step and by this the underlying containers gets access to escalated capabilities like mounting volumes."}),"\n",(0,o.jsx)(t.admonition,{type:"note",children:(0,o.jsx)(t.p,{children:"Only server admins can set this option. If you are not a server admin this option won't be shown in your project settings."})}),"\n",(0,o.jsx)(t.h2,{id:"custom-trusted-clone-plugins",children:"Custom trusted clone plugins"}),"\n",(0,o.jsxs)(t.p,{children:["During the clone process, Git credentials (e.g., for private repositories) may be required.\nThese credentials are provided via ",(0,o.jsx)(t.a,{href:"https://everything.curl.dev/usingcurl/netrc.html",children:(0,o.jsx)(t.code,{children:"netrc"})}),"."]}),"\n",(0,o.jsxs)(t.p,{children:["These credentials are injected only into trusted plugins specified in the environment variable ",(0,o.jsx)(t.code,{children:"WOODPECKER_PLUGINS_TRUSTED_CLONE"})," (an instance-wide Woodpecker server setting) or declared in this repository-level setting."]}),"\n",(0,o.jsx)(t.p,{children:"With these credentials, it\u2019s possible to perform any Git operations, including pushing changes back to the repo.\nTo prevent unauthorized access or misuse, a plugin allowlist is required, either on the instance level or the repository level.\nWithout an explicit allowlist, a malicious contributor could exploit a custom clone plugin in a Pull Request to reveal or transfer these credentials during the clone step."}),"\n",(0,o.jsx)(t.admonition,{type:"info",children:(0,o.jsxs)(t.p,{children:["This setting does not affect subsequent steps, nor does it allow direct pushes to the repository.\nTo enable pushing changes, you can inject Git credentials as a secret or use a dedicated plugin, such as ",(0,o.jsx)(t.a,{href:"https://woodpecker-ci.org/plugins/git-push",children:"appleboy/drone-git-push"}),"."]})}),"\n",(0,o.jsx)(t.h2,{id:"project-visibility",children:"Project visibility"}),"\n",(0,o.jsx)(t.p,{children:"You can change the visibility of your project by this setting. If a user has access to a project they can see all builds and their logs and artifacts. Settings, Secrets and Registries can only be accessed by owners."}),"\n",(0,o.jsxs)(t.ul,{children:["\n",(0,o.jsxs)(t.li,{children:[(0,o.jsx)(t.code,{children:"Public"})," Every user can see your project without being logged in."]}),"\n",(0,o.jsxs)(t.li,{children:[(0,o.jsx)(t.code,{children:"Internal"})," Only authenticated users of the Woodpecker instance can see this project."]}),"\n",(0,o.jsxs)(t.li,{children:[(0,o.jsx)(t.code,{children:"Private"})," Only you and other owners of the repository can see this project."]}),"\n"]}),"\n",(0,o.jsx)(t.h2,{id:"timeout",children:"Timeout"}),"\n",(0,o.jsx)(t.p,{children:"After this timeout a pipeline has to finish or will be treated as timed out."}),"\n",(0,o.jsx)(t.h2,{id:"cancel-previous-pipelines",children:"Cancel previous pipelines"}),"\n",(0,o.jsx)(t.p,{children:"By enabling this option for a pipeline event previous pipelines of the same event and context will be canceled before starting the newly triggered one."})]})}function p(e={}){let{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,o.jsx)(t,{...e,children:(0,o.jsx)(d,{...e})}):d(e)}},53643(e,t,i){i.d(t,{A:()=>n});let n=i.p+"assets/images/project-settings-8e697923e1d015cbd56cc01eae58f5a1.png"},23191(e,t,i){i.d(t,{R:()=>r,x:()=>l});var n=i(92990);let o={},s=n.createContext(o);function r(e){let t=n.useContext(s);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function l(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:r(e.components),n.createElement(s.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.