* security(ci): pin third-party GitHub Action
Pin mislav/bump-homebrew-formula-action to a full commit SHA and add Dependabot updates for GitHub Actions.
* ci: fix checkout for fork PRs
Use merge ref for forked pull requests and skip auto-commit when the PR comes from a fork.