This repository contains centrally managed GitHub configuration for the
acg-box organization.
The enterprise dependency-review ruleset runs
.github/workflows/dependency-review.yml for pull requests and merge queues in
every targeted repository. It blocks changes that introduce dependencies with
known high or critical vulnerabilities. Lower-severity findings remain visible
in the workflow report without blocking the merge.
The workflow is maintained only in this repository; individual repositories do not need caller workflows.