Limiting GitHub Permissions

My org is concerned about the security of the GitHub integration since it asks for so many permissions.
Is it possible to limit the integration’s permissions to read-only, or even better just to Issues/PRs? My understanding is that GitHub apps have that ability, but Coda is still an OAuth app.