Replace pnpm-lock.yaml with package-lock.json. pnpm-workspace.yaml's
allowBuilds becomes package.json#allowScripts, which npm 11 gates the same way,
listing only the packages actually present in the tree.
Add a .gitignore: the repository had none, so nothing kept the installed
dependency tree out of version control.
miniflare pins sharp exactly, so sharp could not be upgraded in isolation.
wrangler 4.114.0 depends on miniflare 4.20260722.0, which pins sharp 0.35.2
and clears the libvips advisories (GHSA-f88m-g3jw-g9cj).