Excesive permission for PAT to pull image

Carlos Quintero 120 Reputation points

In the exercise:


it is stated "that Before we can use this Docker image, you will need to generate a personal access token that contains the following permissions:"




The permission write:packages is not needed to pull the Docker image. To follow the least privilege principle, that permission should be removed from the list.

