The publish job now opens a Gitea release for the tag, using the matching Keep-a-Changelog section as the body via scripts/release-notes.sh. It runs before npm publish so a broken page fails CI without burning an npm version; npm publish stays the last step. Uses the first-party gitea-release-action (the older actions/release-action is deprecated and requires asset files) and contents: write for the run's automatic token.