Two jobs:
- checks: runs on every push/PR - lint, tsc --noEmit, and a full
`pnpm build` as the static-check gate.
- publish: only on a tag push, gated on checks passing first. Builds
the Dockerfile and pushes to this instance's container registry
(dev.pivoine.art/<owner>/<repo>) tagged both `latest` and the exact
git tag, using PACKAGE_TOKEN from the runner's own environment to
log in (not a repo secret, per how it's configured on this runner).