Skip to content

figure out the minimal github token permissions for the githubrepo promise #3607

Open

Description

It's really hard to find an answer to the question of which scopes are needed for such token. From the description, it seems we need admin permission, but some comments claim you don't need it. I think we just have to check in an experiment. admin is very broad, as it allows to delete any repo, so skipping it would be a great security improvement.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    • Status

      Inbox 📥

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions