Add more restrictive default permissions to actions for more defence-in-depth. <!-- Warning: The suggested title contains the alert rule name. This can expose security information. --> Tracking issue for: - [ ] https://github.com/reactive-firewall/python-repo/security/code-scanning/83 - [x] https://github.com/reactive-firewall/python-repo/security/code-scanning/84 - [x] https://github.com/reactive-firewall/python-repo/security/code-scanning/85