Two fixes to make main ship an image again:
1. The image job used docker/login-action + build-push-action, which need
a docker binary the runner's default job container does not have (the
exact failure tenant-registry hit in run 5441). Rebuilt on the proven
compliance build-push-deploy pattern: container docker:27-cli, plain
docker login/build/push, cosign, then the HMAC-signed orca webhook
over plain http like the proven compliance trigger-orca job.
2. trivy gate: postcss 8.4.31 (CVE-2026-45623, CVE-2026-73646) and sharp
0.34.5 (GHSA-f88m-g3jw-g9cj) via pnpm overrides; lockfile resolves
postcss 8.5.26 / sharp 0.35.4. Local trivy scan is clean; lint,
typecheck, 100% coverage and build all pass locally.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CNdLL9BdsWm7MCyui5ffPD