SONAR_TOKEN permissions in pull request GitHub Actions

It’s a PR from a fork… which I guess we’ve taken to calling “external PRs” internally.

Some users have crafted some complicated workarounds. You’re welcome to take a look.

This is a topic we’re sure we’ll address someday, but unfortunately, it keeps getting bumped.