metadata-action: one annotations change the repo's
own checks missed.
In a measured replay of six real first-parent commits from
docker/metadata-action, the same selected checks
passed in standard CI every time. DriftFence stayed quiet through
five commits, then flagged one annotations change.
With approved metadata behavior fixed in Git, DriftFence would have started flagging when default OCI annotations began mirroring generated label values and custom annotation inputs started overriding the earlier null description.