Merge pull request #3985 from facebook/scorecard_permission

try to silence some scorecard warnings
diff --git a/.github/workflows/commit.yml b/.github/workflows/commit.yml
index 5fc8cb1..25d8c52 100644
--- a/.github/workflows/commit.yml
+++ b/.github/workflows/commit.yml
@@ -3,6 +3,7 @@
   push:
     branches:
     - dev
+permissions: read-all
 jobs:
   short-tests-0:
     runs-on: ubuntu-latest
diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml
index 9206a07..704e789 100644
--- a/.github/workflows/nightly.yml
+++ b/.github/workflows/nightly.yml
@@ -7,6 +7,7 @@
     - release
     - dev
     - master
+permissions: read-all
 jobs:
   regression-test:
     runs-on: ubuntu-latest