Run Danger on its dedicated Namespace profile (#64632)

## Summary

Run Danger on the preconfigured `namespace-profile-dangerbot` runner
instead of the shared `namespace-profile-2x4-ubuntu-2404` profile. The
dedicated profile lets Namespace inject the Danger proxy credential
through its egress policy without enabling that capability for unrelated
jobs on the shared profile.

Update the Rust workflow generator, generated workflow, and actionlint
runner-label allowlist together. The proxy URL and placeholder GitHub
token remain unchanged. Proxy-side secret validation is a separate
follow-up; this PR only switches the runner profile.

## Validation

- `cargo fmt --package xtask -- --check`
- `cargo xtask workflows` (including generated workflow validation)
- `actionlint -oneline .github/workflows/danger.yml` (v1.7.12)
- `git diff --check`
- Confirmed the `dangerbot` Namespace profile exists with Ubuntu 24.04,
2 CPUs, and 4 GiB RAM.

The first Danger run on this PR will exercise the new profile; local
checks do not verify runtime header injection.

Release Notes:

- N/A
fbb313eb33Conrad Irwin committed on 9/23/2026, 3:10:07 PM· committed by GitHubparenta39324b
4 files changedLine totals unavailable