allstar icon indicating copy to clipboard operation
allstar copied to clipboard

Permissions for Github App seem too permissive for the current functionality

Open testworksau opened this issue 3 years ago • 1 comments

When self-hosting the Allstar app, it seems the permissions required / listed here are a little too permissive.

I'm not sure why it needs read-only access to Environments, Deployments, Pages, Projects, Discussions, Commit Statuses, Secret scanning alerts (not that we have this option) or Webhooks as an example.

testworksau avatar Sep 21 '22 04:09 testworksau

Yes, on the read side, I was liberal to future-proof against any new policies that could be added.

jeffmendoza avatar Sep 21 '22 18:09 jeffmendoza