Epic: #14 ## Goal Make supply-chain workflow pass reliably. ## Acceptance Criteria - [ ] SLSA generator permissions fixed. - [ ] SBOM generation succeeds. - [ ] No deprecated actions.