Fine-grained PATs currently require you to be a member of an Organization, in order to mint a token that targets repos in that Organization. However, in open source workflows it's quite common for users to not be a member of the Organization they're contributing to. This work permits a fine-grained PAT to be used against repositories in an Organization that the user is not a member of, including repositories that the user is an Outside Collaborator on
Intended Outcome
Developers can mint a fine-grained PAT that targets all open-source repositories. They can choose any of the fine-grained permissions available on repositories. Their access to the repository will be determined by both these permissions as well as the settings on the repository.
How will it work?
The UI is still being determined, but developers will likely be able to create a PAT that's not targeted to their personal account or an Organization, but instead "all other / public repos". Alternatively, they may be able to tick a checkbox which indicates that the token they're creating is targeted to both the targeted Organizations and repositories as well as all public repositories.
The text was updated successfully, but these errors were encountered:
github-product-roadmap commentedNov 16, 2022
Summary
Fine-grained PATs currently require you to be a member of an Organization, in order to mint a token that targets repos in that Organization. However, in open source workflows it's quite common for users to not be a member of the Organization they're contributing to. This work permits a fine-grained PAT to be used against repositories in an Organization that the user is not a member of, including repositories that the user is an Outside Collaborator on
Intended Outcome
Developers can mint a fine-grained PAT that targets all open-source repositories. They can choose any of the fine-grained permissions available on repositories. Their access to the repository will be determined by both these permissions as well as the settings on the repository.
How will it work?
The UI is still being determined, but developers will likely be able to create a PAT that's not targeted to their personal account or an Organization, but instead "all other / public repos". Alternatively, they may be able to tick a checkbox which indicates that the token they're creating is targeted to both the targeted Organizations and repositories as well as all public repositories.
The text was updated successfully, but these errors were encountered: