Skip to content

Document the security model#45

Merged
GrahamCampbell merged 1 commit into
mainfrom
document-security-model
Jun 12, 2026
Merged

Document the security model#45
GrahamCampbell merged 1 commit into
mainfrom
document-security-model

Conversation

@GrahamCampbell

Copy link
Copy Markdown
Contributor

The README explains proxy and timeout behaviour but says nothing about the trust model. This adds a short paragraph in the same style noting that a Compose project is code: JavaScript and TypeScript configurations execute on load, and deployments run the osls CLI in each service directory, so projects from untrusted sources should not be run. The paragraph links to the osls security guide and to the new security section of the Compose documentation, keeping with this README's role as a pointer to the docs that live in the osls repository.

@GrahamCampbell GrahamCampbell merged commit 6c9e6f6 into main Jun 12, 2026
4 checks passed
@GrahamCampbell GrahamCampbell deleted the document-security-model branch June 12, 2026 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant