Command differs locally vs CI
Use the same Python minor and the same py -3.12 -m manifestguard ... invocation. Point --project-python at the project venv; do not pip-install a second CLI into .venv.
Pro still looks like Community
pip install --upgrade manifestguard from public PyPI only refreshes Community. After a Pro purchase use license update-check then license update-apply, then --version in that interpreter.
Too many findings
Stabilize check first. Add --extended when the baseline is quiet. Do not fail the gate on every warning on day one.
py -3.12 -m manifestguard --version
py -3.12 -m manifestguard license status
py -3.12 -m manifestguard check