private/ci gained the fix that makes ci-composer-audit / ci-composer-validate follow a project's shared-workflow pin (`uses: private/ci/.../php-test.yaml@v1`) instead of grepping for inline workflow text that an adopted repo no longer contains. That file is VENDORED into this repo at .ci/ (by design — §8.2, so CI never fetches from the LAN-only private/ci at run time), so moving the v1 tag updated the workflow but not this copy. Re-vendored with sync-configs.sh. Before: 2 of 34 checks failed (the two false positives). After: All 35 runnable checks passed. Also brings .ci/validate-bake.py, which the new checker's bake-target-exists check needs; without it that check correctly reports SKIPPED rather than silently passing.