Trigger wiring: MR create and draft-to-ready

Part of Customer Zero of MR Risk Assessment.

Why this exists

A classification needs a moment to start. Without a trigger, nothing ever calls the flow, and no merge request gets assessed. The trigger also has to leave a draft alone, because its author is still writing the diff, and it must never slow down or fail merge request creation.

What you should see

The flow trigger platform starts a classification. The flow definition declares triggers: for merge_request (on open) and merge_request_ready (draft marked ready). A draft merge request is not classified until it is marked ready.

The run is asynchronous and independent of Duo Code Review. It cannot slow down or fail merge request creation.

The diff SHA reaches the flow through the shared resource context. This ties the classification result to the revision it actually describes, so a later diff cannot be scored against an earlier assessment or the reverse.

A previously separate feature flag for the trigger, merge_request_create_flow_trigger, was removed. The trigger is unconditional now. Only duo_mr_risk_classification needs to be enabled to see it fire.

Delivered by !254545 (merged), with flow availability added in !253771 (merged) and the revision fix carried in !254877 (merged).

Edited by Wanderson Policarpo