Replace pnpm-lock.yaml with package-lock.json. pnpm-workspace.yaml's
allowBuilds becomes package.json#allowScripts, which npm 11 gates the same
way; sharp is omitted because it is no longer in the dependency tree.
Excludes node_modules, .wrangler, logs, OS cruft, and dotenv-style secret
files. .dev.vars is the wrangler dev source for TELEGRAM_TOKEN and
TELEGRAM_CHAT_ID, so keep it out of history.
Adds an llmstxt.org-format usage spec at the repo root, bundled into the
worker as a text module and served at GET /llms.txt. /llms.txt is the only
GET route; all other GETs still return 405, so crawlers and link previews
cannot trigger a Telegram message.
sharp was pinned transitively via wrangler -> miniflare below the
0.35.0 security fix. Bumping wrangler resolves the advisory without
any source change.
CI uses pnpm install --frozen-lockfile which enforces strictDepBuilds;
sharp is a transitive dep with postinstall, so it must be explicitly
allowed too. Local pnpm install --force masked this previously.
Enrichment (IP, UA, geo, timezone, URL, timestamp) is now handled by
miti-loki. miti-telegram becomes a minimal text-passthrough so callers
can format messages however they want without the worker mutating them.