Harden GitHub workflow permissions

- Restrict release workflow defaults to read-only access
- Grant `id-token` only to the publish job
- Document safe handling for `pull_request_target` in PR size checks
Browse files
JMJulius Marminge committed 4 months ago556c424parent 7e20b23