Skip to content

What pemission scopes does the action need for the generated GITHUB_TOKEN? #220

@ghost

Description

Hello there, hope everything is fine

I was wondering which permission scopes should I grant for the PAT (personal access token) of changesets action.
Below is the list of permission scopes available for PATs, I have some ambiguity to choose some of them.

image
image

And there's also some problem with this approach of giving PAT as github_token to the action, since the PAT gives access to all repos and you can't limit the scope.
Isn't there any better approach for that?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions