5b88e69c40
Runs on push/PR to codex/staging-baseline plus manual dispatch: sbt test for the backend, and npm ci/typecheck/build/audit (full + production-only) for the frontend, matching the checks already documented as the manual Rocky verification routine. Verified sbt test compiles and passes with no .env file present (matching what a checkout-only CI job will actually have) via a git-archive dry run before writing this. Two separate jobs, each with its own container image, rather than one shared runner-label image with ad-hoc installs — reuses the exact hseeberger/scala-sbt image already used all session for local backend builds, and a plain node:20-bookworm for the frontend, so nothing needs apt-get bootstrapping of a second language runtime into the same container.