Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -188,6 +188,13 @@ is for.
**Security reports are the exception** and are genuinely wanted: see
[SECURITY.md](SECURITY.md).

## Maintenance

This repository is exported from the 577i-unified monorepo by its
`scripts/export-forge-intelligence.ts`; it is never edited directly and never
merged back, so dependency updates arrive through the next export rather than
through pull requests here. CI runs install + build on every PR.
Comment on lines +195 to +196

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Clarify the Dependabot PR exceptions

This absolute statement contradicts .github/dependabot.yml:3-16: npm security-update PRs remain enabled, and the GitHub Actions ecosystem is scheduled to create monthly dependency-update PRs. When either type of update is opened, maintainers are incorrectly told that dependency changes only arrive through exports and not through PRs; document these automated exceptions so valid security and workflow updates are not mistaken for unsupported contributions.

Useful? React with 👍 / 👎.


---

<div align="center">
Expand Down
2 changes: 1 addition & 1 deletion docs/data-sources.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Every upstream feed the console consumes, with its licence and commercial
status. This file is the answer to "can we ship this?" — if a source is not
listed here, it is not wired in.

Two rules govern the inventory, and both are load-bearing:
Two rules govern the inventory, and both are binding:

1. **Commercial-use clean.** 577 Industries is a commercial entity, so a
source that is free only for non-commercial use is disqualified regardless
Expand Down
2 changes: 1 addition & 1 deletion next.config.ts
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
import type { NextConfig } from "next";

/**
* Content-Security-Policy is load-bearing here, not boilerplate.
* Content-Security-Policy is the security boundary of this app, not boilerplate.
*
* `connect-src 'self'` is why /api/intelligence/tiles exists: the browser
* cannot reach a tile CDN directly, so the basemap is proxied through a
Expand Down