Checks in JSON specs for three rulesets (main-protection,
release-branches, tag-immutability), a CODEOWNERS file (advisory),
and scripts/sync-rulesets.sh to apply them.
Enforcement is `disabled` in all three files — PR-2 will apply with
`evaluate` for a 1-week dry-run, PR-3 will flip to `active`.
See docs/branch-protection.md for the full rollout plan.