ab5216f6c7
The publish workflow used to bump npm latest+1 *before* attempting the platform publishes. When a platform package was missing its trusted-publisher config the version was already incremented but that platform never shipped, leaving partial-publish garbage versions on npm (this happened with v3.17.7-v3.17.9 during the OIDC migration). Add a preflight-trust job that runs in parallel with test/typecheck and verifies all 24 packages have a trusted publisher configured by calling npm's own OIDC token exchange endpoint with the workflow's GitHub OIDC token. publish-main now needs preflight-trust, so any missing trust config fails the workflow before the version bump. Failure output lists the exact npm.com URLs to configure each missing package, plus the org/repo/workflow values to enter.