Run the publish workflow from the workflow_run event so Docker publishing happens only after the CI workflow completes successfully for push events on main or v* tags.
Check out the exact SHA validated by CI and derive Docker metadata from the upstream CI ref, so publishing follows the tested revision instead of the default branch tip.
This supersedes 7d183b9 ("Run CI for pull requests"), which mixed validation and publishing in one workflow and regressed docker-manifest by dropping the package-write permission it needs to publish the manifest.
Split the workflows so CI handles pull requests, branch pushes, tags, and manual runs, while publishing stays focused on Docker delivery with the manifest permission fixed explicitly at the job level.
Using the floating stable toolchain currently breaks this project. Repro via just build-debug:
```
Compiling matrix-sdk v0.16.0
error: queries overflow the depth limit!
help: consider increasing the recursion limit by adding #![recursion_limit = "256"] to your crate (matrix_sdk)
note: query depth increased by 130 when computing layout of matrix-sdk Client::sync async body
error: could not compile matrix-sdk (lib) due to 1 previous error
```
Pinning CI to 1.93.0 keeps CI on the known-good toolchain until upstream/toolchain compatibility is addressed.
We should have had that to begin with (we're pinning as much as we can anyway), but..
Ref: https://github.com/etkecc/baibot/pull/83#issuecomment-4008463792