Repository scope stays provider-controlled
GitHub's installation screen determines which repositories the app can access.
The GitHub workflow uses selected GitHub App installation scope and short-lived tokens for supported code and repository-control validations.
GitHub's installation screen determines which repositories the app can access.
Code validation examines repository content; configuration audit reads supported GitHub controls.
History and a later validation show whether supported evidence changed.
No. The hosted workflow uses a GitHub App.
Yes, when it is in the authorized GitHub App installation scope.