"message": "ci: limit default permissions to contents.read (#1447)\n\nThis change refactors all root pipelines (`trunk` and `presubmit`) to\nlimit the contents permission to read. By default, GitHub has taken the\noverly-permissive approach of granting all permissions if the\n`permissions` map is not explicitly defined. Usability wins out over\nsecurity, again.\n\nChange-Id: Idaca851385fb82eefd6c7c9b8ee46b85a3f4901c",