The contributor-credit script only ever scanned CHANGELOG.md text for
issue/PR numbers. An issue linked to a PR only through GitHub's
Development sidebar (no typed "closes #N" anywhere) never produces
any text to scan, so its external opener was silently never credited.
Query the GitHub GraphQL API for each changelog PR's closingIssuesReferences
and credit those openers under the PR's own visible bullet.
Release publish runs leave steps.release.outputs.pr empty, so fromJSON crashed
even when the credit step was gated off. Credit external issue openers with an
inline thanks suffix on logical changelog bullets instead of a Thanks section.
Keep fatal API lookup logs status-only.