The Nixpkgs Security Tracker currently uses an action (upstream action) to create a GitHub app token as part of its CI pipeline. We need someone with GH org access to register a new GitHub App on the org-level as described in the Action's README and let us know of the generated secrets. The scope of the app should be limited to the https://github.com/NixOS/nix-security-tracker/ repository only.
Related to NixOS/nix-security-tracker#677