The prior pattern relying on steps.semantic-release.outputs did not
fire. Move the publish dispatch into @semantic-release/exec successCmd,
which runs only after a release is actually published and has
nextRelease.version available. Also add GH_TOKEN env for gh CLI
(GITHUB_TOKEN alone is not read by gh).
cargo check --locked fails after bumping version in Cargo.toml because
Cargo.lock needs to be regenerated with the new root package version.
Semantic-release bump then committed Cargo.toml+CHANGELOG but lockfile
stayed stale, so the whole prepare step errored out.
- Add .releaserc.json: conventional commits -> semantic version bump
(major/minor/patch), updates Cargo.toml + Cargo.lock version, writes
CHANGELOG.md, commits as 'chore(release): X.Y.Z [skip ci]'
- Add release.yml: runs semantic-release on main push, then triggers
publish.yml via workflow_dispatch with the new tag
- Update publish.yml: add workflow_dispatch input (tag) so release
workflow can trigger publish directly (GITHUB_TOKEN tag pushes do not
trigger 'on: push: tags'); still supports manual tag pushes