From 1f790b6cdb75d9b8b398c326db31e976b00170bb Mon Sep 17 00:00:00 2001 From: NiftyAndy Date: Tue, 28 Jul 2026 03:37:09 -0400 Subject: [PATCH] feat(security): document centralized security runtime --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index 3967f86..ff70eb1 100644 --- a/README.md +++ b/README.md @@ -42,6 +42,10 @@ the selected repository is saved in `.github/template.yml` and rendered into the small `ci.yml` and `test.yml` wrappers automatically. The equivalent environment variable is `REPO_FOUNDRY_RUNTIME_REPOSITORY`. +The standard Security wrapper uses the same runtime contract, so dependency +audits and the public-only Dependency Review policy can be upgraded centrally +without copying security scripts into every consumer repository. + Initialization defaults to AGPL for new repositories. Synchronization defaults to `--license preserve`, so an existing repository's license is never replaced unless you explicitly select a license or provide `--license-file`.