feat(scripts): add image.sh, which says which local build is in play master
A machine that has built this repo for a week holds thirty tags across two Suramadu versions and one renaming, and the tag string is the only thing telling them apart. `list` prints what is on disk with the facts that decide: the size `docker image inspect` reports, the commit the tag encodes, and whether that commit is still one you can `git show`. `resolve` turns a selector - the tag versions.env names, an exact tag, a short sha, or "newest" - into one reference on stdout and nothing else, so anything that needs an image can ask here instead of composing IMAGE_NAME and IMAGE_TAG. It fails when the image is not there, and names build.sh when the miss is the ordinary one. `diff` compares two builds read-only, and `--deep` reads versions.env out of them with the throwaway container run.sh already uses. Two things the daemon will not tell you straight. Tags sharing an image id are one row, because `latest` and a sha tag are one set of layers. And several builds carry the same Created timestamp to the nanosecond, which `docker image ls` orders differently every run - so the sort is ours, and `newest` breaks the ties with git rather than guessing. Nothing here removes an image.