ignore tests in CodeQL scan and add missing permission restrictions Signed-off-by: gruebel <anton.gruebel@gmail.com>