Add unified CI/CD pipeline with supply chain security
Consolidate separate test, lint, e2e, and image workflows into a single build pipeline modeled after 5-spot. Adds Cosign image signing, SBOM generation, Trivy container scanning, govulncheck, SLSA Level 3 provenance, GitHub Artifact Attestation, multi-arch builds, and automated release asset upload. Fix all outstanding lint issues. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By:
Claude Opus 4.6 (1M context) <noreply@anthropic.com>