agreed… why can an ID token for a separate client application be used to read and write to GitHub? that’s the story here.
Not checking the "audience" of a token or misconfiguring it is pretty common. A lot of applications don't actually check it.
Not checking the "audience" of a token or misconfiguring it is pretty common. A lot of applications don't actually check it.