This restricts the GITHUB_TOKEN to least-privilege in all workflows, fixing CodeQL code-scanning alerts for actions/missing-workflow-permissions.