Give the workflow contents/pull-requests/issues write permissions so the OIDC app token can push. Also point to @main instead of @v1.
Give the workflow contents/pull-requests/issues write permissions so the OIDC app token can push. Also point to @main instead of @v1.