Skip to content
Discussion options

You must be logged in to vote

The only workaround I have found is to create a separate new user, with no packages, and then, from the main user account, give that new user read and write permissions for the specific package or packages you want. Then, create a Personal Access Token (classic) with packages:read and packages:write permissions. Now, use that new user PAT to access the package in the main user account that you have granted permissions for.

Because the need for least permissions is such an obvious best practice, and would be needed for every automation (e.g. with kamal), it is frankly hard for me to believe that this is beyond what GitHub can do without this kludgy workaround. Hopefully I am wrong, and I j…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by nachbar
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Packages Host your dependencies, libraries, and production-ready code, right from your repository Question Ask and answer questions about GitHub features and usage inactive This discussion has been automatically marked as inactive. This was formerly labeled stale.
1 participant