* constrain auto-close and enforce-dependency-review triggers
we don't need to run these on PR close or when we apply labels, for example
* skip workflows on push to dependabot branch
* use PAT if available else fall back to workflow token
* further constrain pull_request triggers
Co-authored-by: repo-ranger[bot] <39074581+repo-ranger[bot]@users.noreply.github.com>