See https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#token-permissions
Although we run `setup-gradle` with all/most wrapper files, this global workflow will ensure that all wrapper files in the repo are valid. (This should help with the OSSF scorecard)