README: plainer wording

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-28 14:52:15 -04:00
co-authored by Claude Opus 5.5
parent 0526dc283a
commit 6a87d32108
+1 -2
View File
@@ -16,8 +16,7 @@ themselves. The failures tend to be the same three.
1. The pull nobody counted. A build that "just pulls a base image" can move
hundreds of megabytes to a third-party registry. It does not show up in
the plan because nobody wrote it as a step; it is a side effect of one. A
step with `bytes: null` is NOT ASSESSED, never zero. An unmeasured
transfer is not a small one.
step with `bytes: null` is NOT ASSESSED, never zero.
2. Egress outside the declared set. An allowlist exists because a deploy
that reaches an unexpected host is either a supply-chain problem or a
leak. That check runs first and stays critical however small the transfer