support semver checkpoint formats
Commit

Parse checkpoint policy versions with golang.org/x/mod/semver so downgrade checks can compare minor, patch, and prerelease versions.
Keep read/write support explicit while canonicalizing equivalent branch-v1 forms through the format key.
Entire-Checkpoint: 5b9a51224543
Checkpoints
Checkpoint 1