Stability checkpoint — auto-merge dev→main feature + workflow rules dev fix

- feat(ci): include auto-merge-dev-to-main template (iris-common)
- fix(ci): workflow rules match dev branch (was main-only)
- test(order): OrderStatusTest enum sanity tests (recovered from feature/order-entity)
- chore(submodule): iris-common SHA bump 8e8eabd → cf8c973 (gcc fix, conv-commits 100, skip merge commits)

- ✅ Main pipeline post-merge green
- ✅ Auto-merge dev → main fires correctly (allow_force_push + AUTOMERGE_TOKEN protected)
- ✅ grype:scan 0 CVEs
- ✅ All gates green (shellcheck, adr-drift, conv-commits, code-quality, sonar, integration-test, unit-test, docker-build, build-jar)

- 🔄 CI/CD : 🆕 auto-merge dev → main template (eliminates manual promote MRs)
- ✅ Qualité : OrderStatusTest enum sanity (carry-over from old branch, +1 file)
- 🏛 Architecture : iris-common SHA bumped (template + script updates)

- Compat matrix SB3/SB4 × Java17/21/25 still `manual` (regression baseline)

- Compat matrix on scheduled cadence (daily/weekly)
- GH Actions parity for double-CI