We recently tried out Jira - GitLab integration using GitLab for Jira Cloud. This all works fine but don't you agree that giving Jira Cloud an access token with complete api access poses a security threat? I guess with GitHub it's the same.
How do you do this? Is it possible to restrict access from Jira Cloud so that not the complete repository can be downloaded, and make the integration still work? Do you simply accept the fact because the advantages outweigh the risk?
Cheers,
Kirstin