Replacing PAT with GitHub App

I thought that using the same PAT is the recommended approach? Or are you just acknowledging that while recommended, is still a security vulnerability?