The organization profile, and the files every osapi-io repository falls back to.
Two jobs: the page people land on, and the files repositories inherit.
Nothing here is built or imported. GitHub reads this repository by name and by path, so where a file sits decides what it does.
profile/README.md is rendered at github.com/osapi-io.
No other file in this repository appears there, and the file has no effect
anywhere else.
Everything at the root is a community health file. GitHub serves one to any repository in the organization that does not have its own copy. It never replaces a copy a repository already has, so adding a file here changes nothing for a repository that carries its own.
That distinction matters for what is actually in use today:
| File | Served to | Also carried by |
|---|---|---|
| SECURITY.md | all seven repositories | none of them |
| CODE_OF_CONDUCT.md | nothing | all seven |
| AI_POLICY.md | nothing | all seven |
| LICENSE | nothing, GitHub has no license fallback | all seven |
So SECURITY.md is the only one doing the fallback job. The other three exist
as the organization's canonical copy, which is what the profile page links
rather than picking one repository's copy and implying it speaks for the rest.
AI_POLICY.md is not a file GitHub recognizes. It is served to nobody and
inherited by nobody. It is here to be linked.
Edit profile/README.md. It takes effect on merge, with no build step and no
deploy. The wordmark beside it is profile/asset/logo-dark.svg and its light
counterpart, drawn from the five colours in osapi's logo like every sister
repository's.
Every link in that file is absolute. The page is served from the organization URL rather than from this repository, so a relative link there is not worth finding out the hard way.
The MIT License.