github: use DeterminateSystems nix installer
github: run cicid on prs
github/flake-update-inputs: use PAT to trigger subsequent workflows
github: simplify workflow runs
github: setup git after checkout
github/flake-update-inputs: don't self assign reviews
github/git-sync-mirrors: only run on master
github: don't sync to codeberg
github: only run nix checks on .nix updates
github: only run nix checks on .nix and .lock updates
github: ignore .github and _img paths