Skip to content

docs: clarify security scope and hardening guidance#101

Merged
sebastianwessel merged 1 commit into
mainfrom
codex/docs-security-model
Feb 13, 2026
Merged

docs: clarify security scope and hardening guidance#101
sebastianwessel merged 1 commit into
mainfrom
codex/docs-security-model

Conversation

@sebastianwessel
Copy link
Copy Markdown
Owner

@sebastianwessel sebastianwessel commented Feb 13, 2026

Summary

  • add new docs page: Security Model & Hardening
  • clarify project scope: wrapper/sandbox layer vs upstream QuickJS engine vulnerabilities
  • add practical defense-in-depth recommendations for production deployments
  • link the new guidance from:
    • docs/index.md
    • docs/basic-understanding.md
    • docs/fetch.md

Why

Issue #99 raised concerns around QuickJS exploitability. This change documents the threat model clearly and provides concrete hardening guidance for users running untrusted code.

@sebastianwessel sebastianwessel merged commit 5c99e31 into main Feb 13, 2026
2 checks passed
@sebastianwessel sebastianwessel deleted the codex/docs-security-model branch February 13, 2026 14:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant