v10.1.0 — stop lint-containerfile + detect-changes contending for anvil MINOR: no input added, removed, or renamed. Two instance jobs move off the runner_tag input onto a hardcoded SaaS tag; every consumer's own .gitlab-ci.yml needs no change to pick this up on its next pin bump. instance's lint-containerfile and detect-changes jobs shared the runner_tag input with the hardware-bound build job. All 8 instance consumers set runner_tag: anvil (the estate's single self-hosted qemu host), so both lightweight jobs queued behind real image builds on the same single machine. Measured over 30 days: lint-containerfile + detect-changes were 2.5% of anvil's compute but 49% of its total queue wait across those 8 consumers. Worst case: roon-bootc's lint queued 52.3 minutes for 1 minute of work, and because stages run sequentially that dragged build/detect-changes behind it too. Neither job needs anvil: hadolint is a static lint and detect-changes is a skopeo inspect registry digest check -- no privilege, no host state, no credential beyond the job token. Hardcoded both jobs' tags to saas-linux-small-amd64 rather than dropping tags entirely or adding a new spec:inputs override. Confirmed via the runners API that the self-hosted storr runner (id 50689664) registers itself under every GitLab SaaS size tag AND has run_untagged: true, so a bare/untagged job is not guaranteed to land on genuine SaaS either -- an explicit tag is no more or less ambiguous on that axis, but it is self-documenting and (also runners-API-confirmed) structurally guaranteed to never touch anvil: anvil's tag_list is [lodestone, qemu, anvil] with run_untagged: false. small, not runner_tag's large default: both jobs are sub-minute work, right-sized the way vm_size is for build. No new input added: neither job has a real per-consumer reason to diverge, so a lint_runner_tag-style knob would be a moving part no consumer would ever set. build and promote are untouched. Verified via POST ci/lint against a real consumer's content (example-plain), before vs. after: only lint-containerfile and detect-changes tags changed (anvil -> saas-linux-small-amd64); build stayed anvil, promote stayed crucible. This catalog's own consumer-shape-gate child pipeline -- a real pipeline-creation + detect-changes execution -- passed against the fix branch, and both the branch pipeline and post-merge main pipeline (seal-self-test, consumer-test-build/verify/cleanup, release-check, verify-release-image-toolchain, consumer-shape-gate) were job-level green. Also folds in the prior Unreleased content: verify-release-image-toolchain (always-on toolchain check against create-release's image, closing the gap that let a bad gitlab-org/cli digest bump land unverified until the next tag), the .release-image/&release-image pin refactor, and the qcow2-bake/installer-anaconda-iso rootfs default change (xfs -> ext4, fs-verity requirement). See CHANGELOG.md for the full entry.