The build job regenerates schema.json and diffs it against the checked-in
copy, to catch a resources.go edit that never got a `make tfgen`. The comment
above it claimed the schema carries no version. It does: tfgen writes the
upstream version into `packageDescription`.
So the job, which builds at the Makefile's default VERSION, regenerated a
schema stamped v0.1.0 and diffed it against the committed v0.2.0 one. The
v0.2.0 push failed on a mismatch that had nothing to do with the mapping.
Bump the default to match the committed schema and say plainly in both places
that the two move together. Verified by running the job's exact command --
`make provider` with no override, then the diff -- which now exits 0.
The release job was unaffected: it derives VERSION from the tag.