See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions. Setting the most restrictive `permissions` makes this explicit and thus easier to review and more secure.