* fix(release): record dependency advisories without blocking releases
Release dependency evidence now blocks only on known malware. Vulnerability
advisories of every severity are recorded in the evidence summary and surfaced
as GitHub warning annotations, and CI dispatched by Full Release Validation or
release publication reports a failing production audit as a warning. The
per-release risk-acceptance table existed only to accept advisory blockers and
is removed.
The release skills also record that main CI health never gates a release and
that every failed test gets an explicit real-blocker-or-flake decision.
* fix(ci): keep release audit relaxation within the workflow size budget
ci.yml sits at the 480000-byte guard, so the release-dispatch check moves
into a trusted harness script that security-fast already checks out.