TowerGit ↔ CI/CD Pipeline: Least‑Privilege Authentication vs Expired Credentials
Goal Implement a CI/CD workflow that uses TowerGit OAuth tokens with the minimal required scopes while ensuring that expired or revoked tokens do not silently allow pipeline execution. Constraints TowerGit exposes OAuth scopes such as read_repository , write_repository , and admin_repository to enforce least‑privilege access. However, the platform does not a