Harden GitHub workflow permissions
- Restrict release workflow defaults to read-only access - Grant `id-token` only to the publish job - Document safe handling for `pull_request_target` in PR size checks
- Restrict release workflow defaults to read-only access - Grant `id-token` only to the publish job - Document safe handling for `pull_request_target` in PR size checks