A classic token (prefix ghp_) has coarse scopes instead of permissions: repo grants full control of every repository you can reach in every organization you belong to, and it can be set never to expire. A leaked one is a skeleton key. It remains the only option for GitHub Packages 29 outside Actions (write:packages), user-owned Projects (project) and repositories where you are only an outside collaborator. This book uses none (not run here), as GitHub 29 recommends. Inside workflows, use the automatic GITHUB_TOKEN (Secrets and Environments). Secret scanning (Secret Scanning) recognizes both token formats and can block a push that contains one.
MENU
Classic Tokens
Classic Personal Access Tokens and Why They Are Discouraged