This will allow us to set the default token permissions to restricted, and thus avoid accidentally introducing over-privileged new workflows.
This action works similar to the npm-update workflow, it creates a PR every Thursday (usually after the Cockpit release) to update the COCKPIT_REPO_COMMIT to the latest version.