github / github/github-mcp-server

The doc should provide a minimum list of permissions for the GitHub Access Token

未關閉
#2,963 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
enhancement request ai review
主要語言
Go
星號
33k
分支
5k
平均合併
2 天 1 小時
30 天內合併 PR
52

描述

### Describe the feature or problem you’d like to solve

A clear and concise description of what the feature or problem is.

- The doc should provide a minimum list of permissions for the GitHub Access Token.
- The current documentation at https://github.com/github/github-mcp-server/blob/v1.7.0/docs/installation-guides/README.md mentions this,

> All installations with Personal Access Tokens (PAT) require: GitHub Personal Access Token (PAT): Create one here
>
> Regardless of which installation method you choose, follow these security guidelines:
>
> Limit Token Scope: Only grant necessary permissions to your GitHub PAT

- However, the list of permissions for `personal access token (classic)` is too long. I think the documentation needs to provide a minimum list of required permissions. See https://github.com/settings/tokens/new .
- Image
- Furthermore, the URL provided in the documentation is for creating the `personal access token (classic)`. I think the documentation should guide users to use the `fine-grained personal access token`, which only allows access to repositories within a specific scope, while the `personal access token (classic)` allows access to all unrelated repositories.
- Image

### Proposed solution

How will it benefit GitHub MCP Server and its users?

- This would obviously reduce the cognitive load.

### Example prompts or workflows (for tools/toolsets only)

If it's a new tool or improvement, share 3–5 example prompts or workflows it would enable. Just enough detail to show the value. Clear, valuable use cases are more likely to get approved.

- Null.

### Additional context

Add any other context like screenshots or mockups are helpful, if applicable.

- Null.

貢獻指南

開啟貢獻指南

研究方向

Start with docs/installation-guides/README.md and review the linked GitHub token creation pages to verify which permissions the server documentation currently assumes. Update the guidance to identify the minimum required permissions and direct users to the appropriate token flow; done means the setup instructions are specific and the least-privilege recommendation is clear.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
github
領域
authentication, documentation, security
Issue 類型
文件
難度
2/5
預估耗時
1-3 小時
活躍度
冷清
描述清晰度
基本清楚
新手友好度
57/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。