GitHub App - why does it need write permission to the repo?

Is there a way to have more fine-grained control of the access we give to Sonatype Lift?

For a tool meant to provide security insights, this feels like exposing clients to excessive risk.

image