Add the PkgbuildRepo type, Configuration.PkgbuildRepos field, and
NormalizePkgbuildRepos to validate repo names and URLs against the
security model: PKGBUILD repos can mask the AUR, so URLs must use a
non-tamperable transport and names must stay within the cache directory.
Wire NormalizePkgbuildRepos into main so config errors surface at
startup. Nothing reads PkgbuildRepos yet; it is only parsed and
validated at this layer.