특정 저장소만 다루는 자동화 계정이나 도구에 GitHub Fine-grained personal access token 을 발급할 때, 파일 생성·수정·삭제와 clone · pull · push 에 필요한 권한은 두 가지뿐이다.
| 권한 | 수준 | 용도 |
|---|---|---|
| Contents | Read and write | 파일 CRUD, clone, pull, push |
| Metadata | Read-only | 저장소 기본 정보. 기본으로 강제 선택된다 |
| 권한 | 수준 | 용도 |
|---|---|---|
| Administration | Read and write | 브랜치 보호, collaborator 관리 등 저장소 설정 |
| Pull requests | Read and write | PR 생성·머지 |
| Issues | Read and write | 이슈 관리 |
| Workflows | Read and write | .github/workflows 아래 파일 수정 |
Workflows 권한이 없으면 Contents 권한이 있어도 워크플로 파일 push 가 거부된다.
Settings → Developer settings → Personal access tokens → Fine-grained tokens → Generate new token 에서 Repository access 를 "Only select repositories" 로 두고 대상 저장소를 고른 뒤 위 권한을 체크한다.