Make govulncheck schedule-only, don't gate PRs
No upstream fix exists for the docker/docker vulns it found, so
gating PRs just blocks the merge queue over something we can't
act on. Daily scheduled run is the right cadence -- matches the
article's intent.