- a github app which had read permission on issues could elevate its permission to write
- a github app which had read permissions to discussions could elevate its permissions to write.
So far if the org/user would have been compromise they would have seen with issues or conversations containing content from the app.
Since these are only examples, I can imagine the case with major impact would be a contents:read elevate to content write. But again with commit signing, this would also be caught by the user. What did I miss where the impact would have not been visible to the end user/org ?