Two jobs: - checks: runs on every push/PR - lint, tsc --noEmit, and a full `pnpm build` as the static-check gate. - publish: only on a tag push, gated on checks passing first. Builds the Dockerfile and pushes to this instance's container registry (dev.pivoine.art/<owner>/<repo>) tagged both `latest` and the exact git tag, using PACKAGE_TOKEN from the runner's own environment to log in (not a repo secret, per how it's configured on this runner).