chore(ci): bump catalog to v2.5.0 + adopt container-scan-summary + Code-Quality
Bump to v2.5.0 (picks up SBOM ingestion for Dependency List). Adopt container-scan-summary catalog component for LLM-pasteable CVE triage. Add Code-Quality template for MR-widget maintainability hints.