v0.47.1

Docker image scans and Docker Hub metadata are reporting work, not release
gates. Scanner outages, SARIF upload failures, and Docker Hub metadata outages
remain visible without blocking an image push, GitHub Release, or caller jobs.

Grype now uses anchore/scan-action v7.4.2.