README: plainer wording
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -16,8 +16,7 @@ themselves. The failures tend to be the same three.
|
|||||||
1. The pull nobody counted. A build that "just pulls a base image" can move
|
1. The pull nobody counted. A build that "just pulls a base image" can move
|
||||||
hundreds of megabytes to a third-party registry. It does not show up in
|
hundreds of megabytes to a third-party registry. It does not show up in
|
||||||
the plan because nobody wrote it as a step; it is a side effect of one. A
|
the plan because nobody wrote it as a step; it is a side effect of one. A
|
||||||
step with `bytes: null` is NOT ASSESSED, never zero. An unmeasured
|
step with `bytes: null` is NOT ASSESSED, never zero.
|
||||||
transfer is not a small one.
|
|
||||||
2. Egress outside the declared set. An allowlist exists because a deploy
|
2. Egress outside the declared set. An allowlist exists because a deploy
|
||||||
that reaches an unexpected host is either a supply-chain problem or a
|
that reaches an unexpected host is either a supply-chain problem or a
|
||||||
leak. That check runs first and stays critical however small the transfer
|
leak. That check runs first and stays critical however small the transfer
|
||||||
|
|||||||
Reference in New Issue
Block a user