From 6a87d321089ad780b1d0ebd68bb7758cb75c50b4 Mon Sep 17 00:00:00 2001 From: Paul Hitt Date: Mon, 28 Sep 2026 14:52:15 -0400 Subject: [PATCH] README: plainer wording Co-Authored-By: Claude Opus 5.5 --- README.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/README.md b/README.md index 3684a8f..d6460b2 100644 --- a/README.md +++ b/README.md @@ -16,8 +16,7 @@ themselves. The failures tend to be the same three. 1. The pull nobody counted. A build that "just pulls a base image" can move hundreds of megabytes to a third-party registry. It does not show up in the plan because nobody wrote it as a step; it is a side effect of one. A - step with `bytes: null` is NOT ASSESSED, never zero. An unmeasured - transfer is not a small one. + step with `bytes: null` is NOT ASSESSED, never zero. 2. Egress outside the declared set. An allowlist exists because a deploy that reaches an unexpected host is either a supply-chain problem or a leak. That check runs first and stays critical however small the transfer