Bring the release boundary up to date with the session's new content
The remote production build refused the previous release candidate
because the archive allowlist predated this session: it was missing
content/public/aphorisms.json (a hard embed failure), the aphorisms
template, the four section-hero delivery sets, and the five newly
published principle slugs with their bodies, art, and share images.
All are now in the fixed allowlist and essential-file inventory, and
the fixture repository covers them.
A new release test expands every //go:embed pattern against the
working tree and requires each matched file to be inside the release
boundary, so a future page or asset series that reaches production
embeds without joining the allowlist fails at commit time instead of
on the production host.