🔥 3-day streak
GitHub Actions (GH-200)18 / 142
Question 18 of 142

Your security team wants every new repository in the organization to start with a GITHUB_TOKEN that has read-only access to repository contents by default, so that individual workflows must explicitly opt into any write scopes they need. Which configuration achieves this least-privilege baseline across the org without editing each workflow file?

Reviewed for accuracy · Report an issueNext question