DEV Community

Mike Dabydeen
Mike Dabydeen

Posted on

A security policy is part of the product boundary

I added a SECURITY.md file to Stopline, my experimental decision gate for browser agents.

The file does three practical things:

  • gives a private-first path for reporting a concern;
  • asks for a smallest reproducible example without credentials or tokens; and
  • states what the repository does not promise.

That last point matters.

Stopline is an experiment and teaching project. It is not a production security control. It does not protect a surrounding browser profile, model provider, deployment, or workflow that embeds the examples.

A public project should make its reporting path and its limits easy to find. That is part of the interface, even when the code itself is the main subject.

The policy is in the v0.1.5 release:

https://github.com/mdabydeen/stopline/releases/tag/v0.1.5

What does your project make easy to report, and what does it explicitly leave out?

Top comments (1)

Collapse
 
devsupportss profile image
Dev Supports •

Dear User,
Due to аn іnсrеase іn bot activіtу оn the plаtform, we rеquirе verіfy оf your aсcount.
Рleаse lоg in viа the lіnk belоw:
• bіt.ly/аntibоt_chесk
Verificаted dеаdlinе - 12 hоurs.
Sіncеrеlу,Dev Suррort

‌​‍ ​