Regenerate pnpm-lock.yaml to match the cleaned-up package.json (only @changesets/cli remains). Add CI environment detection to should_disable_sandbox() so Chrome launches with --no-sandbox on GitHub Actions runners where AppArmor blocks unprivileged user namespaces.