Verify job compiles and tests the Go side with a stubbed dist/, which
main.go embeds and the frontend build produces. Binary job builds the UI
and the real binary.
Living in .forgejo/workflows means Forgejo uses this instead of the 23
upstream .github workflows, which need GitHub-only runner labels.