28cf9faf77
CI only ever built and published. The 44 tests in internal/api ran on a laptop or not at all, so a tag could publish binaries, a container image and a Helm chart from a commit whose tests had never been run — and the tests are the only thing holding several documented contracts in place, including the received_at heartbeat and the alert ordering guard. A test job now runs go vet and go test, and build, docker and chart all depend on it. The release job is downstream of build, so a tag that fails publishes nothing at all rather than publishing three artifacts out of four. chart-release.yml is deliberately left alone. It fires on charts/** pushes and publishes the chart, which contains no Go code and only references an image tag rather than building one, so gating it on the Go suite would add a minute to every chart edit for no signal. This still only runs at release time; nothing checks a push or a pull request, so a broken commit stays green until somebody tags it.