ReleaseNotes.adoc: expand the SBD 'What's New' bullet to call out upgrade.sh's new '-Os'/'-opt-out-of-security-update' options and when they're needed.
Prompted by a real hit of this exact scenario during the BSW Gen6 lab upgrade exercise (2026-09-04): every host had security=0 (a deliberate low-friction training config), and upgrade.sh correctly aborted until '-Os' (plus '-opt-out-of-security-update' on the commit server, to restore security=0 afterward) was used. Worked exactly as designed.
Agent: Claude Sonnet 5 (claude-sonnet-5), via Claude Code.