v10.0.1 — fix the stage v10.0.0 shipped broken, close the gap that let it through

PATCH: v10.0.0's public contract (inputs, job names, the intended
default-behavior change) is unchanged. Only the broken implementation is
fixed. v10.0.0 as tagged was unusable by all seven of its declared
consumers -- none had merged a pin bump to it.

instance's lint-containerfile job (added v10.0.0) landed in a lint stage
declared only in the component's own stages:. A consumer's own top-level
stages: REPLACES the component's wholesale rather than merging with it,
and every real instance consumer declares its own stages:
[detect-changes, build, promote] with no lint -- so lint vanished from
all seven and lint-containerfile referenced a stage that did not exist.
Pipeline CREATION failed outright: 0 jobs, started_at: null, nothing
resembling a lint failure or a YAML error on the pipeline object.

Fixed by moving the job to .pre rather than adding "- lint" to all seven
consumers' stages:, which would have recreated exactly the seven
near-identical deviations this component exists to eliminate. GitLab
injects .pre/.post into the merged stage list unconditionally regardless
of what any consumer's stages: declares, so no consumer override can make
it disappear -- confirmed by ci/lint against a consumer-shaped synthetic
config both before the fix (invalid: chosen stage lint does not exist)
and after (valid, all jobs present in the merged result). instance's own
stages: no longer lists lint.

Three separate pre-landing checks all passed without exercising the
actual failure mode: the hadolint pre-audit validated hadolint's verdict
on real Containerfiles, never the component's own resolvability; a
synthetic-consumer ci/lint run passed because that synthetic consumer did
not declare its own stages: unlike every real one; and this repo's own
consumer-test-build/consumer-test-verify never instantiate a consumer
.gitlab-ci.yml that includes the component alongside its own stages:.

A POST ci/lint-based regression test was built and abandoned before
landing -- it needs the api OAuth scope, and the estate's existing
read_api-scoped token 403s insufficient_scope on that call. No token was
minted or widened to route around this. Closed instead with
consumer-shape-gate: a GitLab child pipeline for a synthetic instance
consumer shaped exactly like the seven real ones, including
instance/supply-chain at $CI_COMMIT_SHA, with strategy: depend
propagating a failed pipeline CREATION back as a red job. Needs no API
call or credential of any kind. Mutation-probed both directions on a real
pipeline: pointed at the broken commit the child pipeline came back
failed/0 jobs with GitLab's own stage-does-not-exist diagnostic; pointed
at the fixed commit it came back success. Runs on every push and tag
pipeline.

release-check -- the guard for kickstart/summary/seal clone- and
ref-literals plus README's component-pin examples -- was manual-only and
CI-unwired; it failed when finally run by hand ahead of the v10.0.0 tag
(all three template literals and four of five README pins were still
v9.4.0, three releases stale) and one README pin stayed stale even in the
v10.0.0 fix commit because the recipe never checked README.md at all.
Wired into every pipeline now: tag pipelines check pins against
CI_COMMIT_TAG exactly, push pipelines check self-referential coherence
against kickstart.yml since there is no tag yet to compare against.

Also fixes two qcow2-bake defects found on the lane's first real CI run
(it had never executed before this release): the bib_image input default
could not resolve the component.version directive inside a default value
(GitLab does not re-interpolate there), now resolved in the job body; and
BIB's devtmpfs mount failed EPERM under SaaS nested DinD, now bound to
the dind daemon's already-populated /dev instead.

Release-prep: bumped the kickstart/summary catalog clone literals, the
seal catalog_ref default, and the README component usage pins v10.0.0 ->
v10.0.1.