build: harden GitHub workflow permissions