Releases: mdabydeen/stopline
Release list
Stopline v0.1.7 — tighten baseline task matching
Stopline v0.1.7
This release tightens the offline keyword baseline's task-fit heuristic.
- Compare exact words from the visible action label.
- Ignore navigation target paths when estimating task fit.
- Add regression tests for repository-path leakage and product-name substring matching.
- Publish the revised 49-case baseline: 0 unsafe allows, 49.0% verdict agreement, 95.9% prompt-injection accuracy, and 100% prompt-injection recall.
The fixture is small and hand-labelled. The keyword backend is a comparison baseline, not a model-backed result, production safety control, or certification.
For a focused team discussion, use the team evaluation guide. It is a zero-credential exercise for recording one action's allow, ask, and block boundary, evidence ownership, recovery ownership, and one bounded next experiment. It does not establish production safety or product demand.
v0.1.6 — team evaluation path
What changed
- Adds a bounded team-evaluation path to the README.
- Keeps the package metadata consistent at v0.1.5 while this release adds documentation only.
- Keeps the free review kit and workshop interest path easy to find.
Boundaries
This is a documentation release. It adds no production-safety, certification, support, demand, or outcome claim.
v0.1.5 — security reporting boundary
What changed
- Added SECURITY.md with a private-first reporting path and a clear scope boundary.
- Linked the policy from the README.
- Explicitly states that Stopline is experimental and not a production security control.
Verification
- 11/11 unit tests pass
- TypeScript typecheck passes
v0.1.4 — offline quick start
What changed
- Added a zero-credential quick start for the labelled keyword baseline.
- Clarified that the offline baseline is a measurement aid, not a safe unattended policy.
- Preserved the model-backed evaluation and explicit evidence boundaries.
Verification
- 11/11 unit tests pass
- TypeScript typecheck passes
- 49-case keyword baseline runs without an API key
Stopline v0.1.3 — revision-bound approval documentation
Stopline v0.1.3
This patch release adds a public, repository-hosted note explaining the revision-bound approval example and how to run it. The README now links the note directly.
The helper and demo remain illustrative building blocks. They do not calculate repository hashes, authenticate approvers, enforce a merge control, or prove that a surrounding workflow cannot bypass them.
Stopline v0.1.2 — runnable revision gate demo
Stopline v0.1.2
This patch release adds npm run demo:revision, a network-free command that prints a matching revision-bound approval and the rejection produced when the proposed revision changes.
The helper remains an illustrative building block. It does not calculate repository hashes, authenticate approvers, enforce a merge control, or prove that a surrounding workflow cannot bypass it.
Stopline v0.1.1 — revision-bound approval example
Stopline v0.1.1
This patch release adds a small, testable revision-bound approval example for delivery-contract discussions.
The helper accepts an approval only when the action identifier, proposed revision, and captured state identifier match. Tests demonstrate the rejection when the revision, state, or action changes after approval.
This is an illustrative building block. It does not calculate repository hashes, authenticate approvers, enforce a merge control, or prove that a surrounding workflow cannot bypass the check.
Stopline v0.1.0 — experimental browser-agent decision gate
Stopline v0.1.0
Stopline is an experimental decision gate for browser agents. It separates model classification from deterministic authorisation: hard rules and policy code decide whether a proposed action is allowed, requires a human, or is blocked.
This initial source release includes:
- the TypeScript gate and policy implementation
- a 49-case labelled evaluation across common browser surfaces
- a repeatable Playwright demo and local fixture site
- JSONL evidence logging
- Jev and local Laya backend paths
- policy tests and setup documentation
The evaluation is an initial measurement on hand-labelled cases. This release is not a production safety certification, and the demo uses a fixed script rather than an LLM planner.
See the README for setup, evaluation commands, limitations, and the related review exercise.