Add ci.yaml triggered on branch pushes and PRs with flutter analyze, flutter test, dart pub audit, Trivy scan, and debug APK build. Gate the release workflow behind a CI job so release builds only proceed after all checks pass. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>