From 647674ff53146144f8f1550142a274ba32b893cd Mon Sep 17 00:00:00 2001 From: NiftyAndy Date: Tue, 28 Jul 2026 03:49:40 -0400 Subject: [PATCH] feat(codeql): document centralized CodeQL runtime --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index ff70eb1f..3dc8f6bf 100644 --- a/README.md +++ b/README.md @@ -46,6 +46,10 @@ The standard Security wrapper uses the same runtime contract, so dependency audits and the public-only Dependency Review policy can be upgraded centrally without copying security scripts into every consumer repository. +CodeQL is also independently reusable through the same contract. It retains +GitHub's native security-event permissions and language-specific analysis while +keeping CodeQL separate from CI and dependency security checks. + Initialization defaults to AGPL for new repositories. Synchronization defaults to `--license preserve`, so an existing repository's license is never replaced unless you explicitly select a license or provide `--license-file`.