chore(release): bump to 0.6.0 and cut the changelog entry

- pyproject.toml: version 0.5.6 -> 0.6.0
- changelog.py: the 0.6.0 entry — vault backup & recovery, the reveal guardrail
  (policy, approvals, audit trail), and the CI-as-unattended caller fix
- CHANGELOG.unreleased.md: reset to its header now that its entries are consumed

The two sections left in the unreleased file (Safe upgrades #43, Typed errors #38) are
deliberately not carried into 0.6.0: both describe work published in 0.5.6 (tagged
2026-09-06, after those PRs merged) and the 0.5.6 entry already covers them. They came
from two changelog PRs that were stranded off main and are redundant with the released
record, so re-listing them would double-list already-published work.
