Sidecat 0.6.0

Source-only command surface and JSON payload cleanup minor release.

This release makes the preferred package surface explicit: sidecat run OBJECT JSON_PAYLOAD, sidecat validate OBJECT, and sidecat template OBJECT for declared package directories. JSON payloads are validated before declared package execution, validate replaces lint as the static-check concept for new work, and templates expose machine-readable call shapes generated from package declarations.

This release also carries the 0.5.x cleanup train: retired imperative git proof deleted from the active tree, serious declarative git sidecat-lorem catfood coverage, AAuth local HTTPS Person Server proof on aauth.sidecat.org, and code-owned anti-sprawl guardrails against noun-grouped command drift.

Not a production runtime, stable command surface, stable package API, hosted identity service, official binary package, signed binary artifact, SBOM, or provenance-backed binary distribution. Noun-grouped package compatibility paths still exist as classified debt.