No mention why this temp token had rights to do things like create a new deployments and generate artifact attestations?
For their fix, they disabled debug logs...but didn't answer if they changed the temp tokens permissions to something more appropriate for a code analysis engine.