How to identify and fix overly powerful GitHub Actions permissions using workflow monitoring
Introducing a new tool to monitor and control the permissions of the repository token for GitHub Actions.

Source: The GitHub Blog
Introducing a new tool to monitor and control the permissions of the repository token for GitHub Actions.