For enhanced security, set explicit permissions for GitHub workflows. This applies to both the primary "caller" workflows and the reusable "callee" workflows they invoke (this repo hosts popular reusable "callee" workflows).
This approach aligns with security best practices, as detailed in the following documentation:
CC @FranzBusch @ktoso