combine-prs icon indicating copy to clipboard operation
combine-prs copied to clipboard

Reword Security Consideration for using a GitHub App

Open dgholz opened this issue 8 months ago • 0 comments

I reworded the section to be more imperative: describe what the user should do to improve the security. And described what privileged access the GitHub App would have (and why), and the potential security concerns.

I also summarised the argument against using separate private keys for the GitHub App to just say 'GitHub App credentials can be used on any repo'. And dropped the mention of fine-grained tokens, as GitHub Apps don't support them.

dgholz avatar Feb 28 '25 12:02 dgholz