Let dependency updates ride routine releases
The routine deploy gate no longer blocks go.mod and go.sum changes
between the live and target revisions. Vet, tests, the reproducible
build, the loopback smoke test, the post-activation HTTPS and
certificate checks, and automatic rollback are the gate for dependency
updates on this site. Changes to cmd/serve.go and
internal/httpserver/production.go still require the manual
ACME-staging and TLS review.