Greetings,
We are looking at connecting the GitHub integration with Compass. We noticed that it wants the following permissions:
* Read access to actions, metadata, and organization events
* Read and write access to code, deployments, organization hooks, pull requests, and repository hooks.
Our SecEng team is looking for a better breakdown of what the possible write actions could be so they could correlate within audit logs.