Add unified CI/CD pipeline with supply chain security

Consolidate separate test, lint, e2e, and image workflows into a single
build pipeline modeled after 5-spot. Adds Cosign image signing, SBOM
generation, Trivy container scanning, govulncheck, SLSA Level 3
provenance, GitHub Artifact Attestation, multi-arch builds, and
automated release asset upload. Fix all outstanding lint issues.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Anthony Green2026-04-18 22:17:18 -0400 19e4829570a72b7df5c8550de1b18abb424790e1
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>