Restrict permissions of github token. Pin action versions. Following advice in briansmith/untrusted#50.