Document private vulnerability reporting and enable weekly npm/Cargo dependency update PRs; link CONTRIBUTING to the new security policy.
Add quick start, repository layout, explicit main vs promotion branches, Tauri boundary as its own section, security handling, Nix/Cachix and non-Linux setup notes, lint/format reality (tsc + clippy), i18n file locations, consolidated hot-path gate wording, and clearer local coverage reproduction steps. Remove redundant summary block.
Document where to ask questions, local commands that mirror CI, PR expectations, caution around disruptive UI, stability of the Tauri Rust-frontend contract, and impact of on-disk settings changes. Link the guide from the README Development section.