chore(ci): bump catalog to v2.1.1 + adopt PST renovate preset
Summary
- Bump
pipeline/{container,verify,release}from@v2.1.0to@v2.1.1. v2.1.1 restores a conditional cosign install in thebinarytemplate for consumers using non-catalogbuild_image. postern only uses the container path (ci-buildah image bundles cosign), so this is fleet- parity rather than functional necessity here. - Replace
renovate.jsonwith the PST shared preset (gitlab>gitlab-com/public-sector-tools/pipeline//presets/renovate.json). Inherits weekly Monday schedule, semantic-commit titles, batched-MR labels, no platform-automerge, UBI + golang group rules. Renovate will pick up Go module bumps and future catalog tags automatically.
Test plan
- MR pipeline green (test, build, scan, verify, release stages)
- No regressions in cosign verify-attestation step
- Pipeline structure unchanged relative to !4 (merged) merge