GitHub apps security

This says for us it has read and write access the repos.

I like it because you don’t need deploy keys.

But what is the philosophy to not have risks with your git repos, across circleci?