Add the public site-stats page and its shipped change log
An unobtrusive "Site stats" link in every footer opens /stats: what is
running now (release commit linking into its own record, build date,
uptime and up-since, changes since inception, inception date, latest
change, serving runtime) above the full change log — twelve entries per
page, newest first, each row opening a per-commit page with the
complete message. A new section hero in the house style crowns the
page: a ledger of light, its entries brightening toward the present.
The log ships inside each release archive: the archive step regenerates
content/public/sitelog.json from the exact target commit, replacing the
committed development placeholder in the tar. Generation records hash,
committer date, and message only; trailers naming collaborators are
stripped; a baked-in redaction list ships subject lines only for three
historic commits whose bodies named the operator or a tool vendor; and
a marker denylist fails the release if any identity or vendor name
would reach the public log, with a repeatable --allow-log-marker
override for innocent occurrences. Tests cover generation, stripping,
redaction, the marker gate, tar replacement, page rendering,
pagination, unknown-commit 404s, no-store caching, and footer links.