* ci: reintroduce Trivy report and gate workflow * ci: add dry-run mode to container release workflow