Container Registry
I have only tested with the most simple use case - publishing containers for that repo only (which is what the example in the preceding link shows).
Use the default provided ${{ secrets.GITHUB_TOKEN }} provided when you run an action on your repo
Make sure permissions are configured in the workflow yaml.$ some foo