Unit tests
- Integration tests
- End-to-end tests
### Code Formatting
- Always ensure that the code is formatted correctly by running prettier before committing changes.
### Branches and Pull Requests
- Unless specifically
history.** No "this used to be X", no bug
archaeology in comments — write code as if it had always been this way.
- **Report facts, then your reading — labelled as yours
seats, and entitlements are organisation-scoped in enterprise.
## UI and Security
- Do not hard-code user-facing strings. Add CE strings to `src/client/src/constants/messages/en.ts`; enterprise-only strings belong in the private
perform opportunistic cleanup.
- **Keep the docs true.** When documentation disagrees with code, verify the code and fix the stale documentation in the same task. Update a topic whenever a change
JAVA-XXXX` matching the Jira ticket (e.g., `JAVA-6143`)
- **Commits:** Keep commits logical and reviewable — each commit should be a coherent unit of change
- **TODO comments:** Must reference a Jira
code
- Do not: modify the C API binding layer without understanding the libmongocrypt contract
## Key Packages
- `com.mongodb.crypt.capi` — mongocryptd C API bindings (JNA) — **security-critical, do not modify without human
review
totals, never their sum.
- Automatic approval applies only to external PR workflow runs, not codereview, merging, or publishing. Agents updating this guide must not remove or weaken these rules
Cycles
For a given task, you should:
1. Research. Search the web, read existing code, look up system/dependency headers / implementations of related functionality. Figure out best practices and common pitfalls
source of truth. If this guide disagrees with the code, follow the code and update the guide; tests document expected behavior and should change only when behavior intentionally changes
bundle is the VM code the route carries as an inline string, while the code hosting it sits in the framework output.
**The gate does not cover the world adapters
compiled
`dist/index.js` for a `browser` target and asserts the output excludes registry-only code,
proving the package.json `sideEffects: false` claim against real compiled output rather than
merely asserting it — plus