- scripts/release.sh: build from main, tag :latest + short SHA, push
both. Aborts if not on main or working tree is dirty; warns on
unpushed commits. Prevents dev states from becoming :latest.
- scripts/dev-build.sh: local dev image (tagged per branch), never
pushed -- keeps development builds off the registry.
- docs/deployment.md: document branch/PR workflow, replace manual
build/push steps with the scripts, SHA-based rollback now standard.
- .gitattributes: force LF on *.sh so the shebang works on Windows.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>