ci: assert the README budget, diagram texts and cosign identity agree
What this does
Three facts in this tree are carried in more than one place on purpose, and nothing compared the copies. scripts/check-versions.sh gains checks 6, 7 and 8, and the version-consistency job already runs the script on every pipeline.
The README word budget was prose in CONTRIBUTING.md's ## Where a fact goes and a word count in README.md. Check 6 asserts wc -w README.md is at most 800, which reads 719 today.
The build-flow diagram exists twice because it renders in two contexts. site/build-flow.svg carries a fixed palette, because README.md embeds it through an <img> that cannot see the host page's CSS, and site/index.html redraws it inline with currentColor so it follows the site's theme toggle. Neither copy serves the other's reader, so both stay. Check 7 compares the ordered sequence of <text> contents, 16 elements today, so the viewBox, coordinates and styling stay free to differ.
The cosign identity regexp and the --certificate-oidc-issuer value are arguments a reader pastes, not prose about the images, so they belong in every file showing a verify command: README.md, SECURITY.md, site/index.html, scripts/tag-release.sh. Check 8 asserts one distinct identity and one distinct issuer across the four, and fails on a file that has lost either, so a deletion is noticed.
Extraction is one sed: the job runs on alpine:3.24 with bash coreutils curl jq, which ships no XML parser.
Verification
Each check was broken in one copy, run, and restored:
check-versions: README.md is 809 words, over the 800-word budget CONTRIBUTING.md sets under 'Where a fact goes'; move the detail to SECURITY.md or site/index.html and link to it
check-versions: site/build-flow.svg and site/index.html disagree on diagram text: < 6 variants per release > 7 variants per release
check-versions: the cosign identity regexp disagrees across README.md SECURITY.md site/index.html scripts/tag-release.sh: ^https://gitlab\.com/gitlab-com/public-sector/kaniko//\.gitlab-ci\.yml@refs/tags/v[0-9].*$ | ^https://gitlab\.com/gitlab-com/public-sector/kanikoX//\.gitlab-ci\.yml@refs/tags/v[0-9].*$The script exits 1 on each and 0 after git checkout of the file. shellcheck is clean, and both paths were run inside alpine:3.24 with the job's dependency set.
Pipeline
This MR touches scripts/, so its own pipeline matches the image-job rules:changes gate and rebuilds all six variants, about 45 minutes. That is accepted here. .gitlab-ci.yml is unchanged, because the job already runs the script.