It seems "checks" is the permissions it needs to be able to comment on pull-requests.
cachix/install-nix-action
actions/checkout