server enables hot-reload for quick iteration
- Production builds are optimized and minified
### Security Notes
- No sensitive data or credentials should be committed
- Use environment variables for any API keys
server enables hot-reload for quick iteration
- Production builds are optimized and minified
### Security Notes
- No sensitive data or credentials should be committed
- Use environment variables for any API keys
server dey enable hot-reload for quick iteration
- Production builds dey optimized and minified
### Security Notes
- No sensitive data or credentials suppose dey committed
- Use environment variables
kredensyal ng Azure account
- Panatilihing updated ang mga dependencies para sa mga security patch
## Pag-aambag sa Mga Pagsasalin
- Ang mga automated na pagsasalin ay pinamamahalaan sa pamamagitan ng GitHub
names the concrete defect and the fix.
- Recommend blocking only for concrete correctness, security, or agreed-contract
defects with a realistic failure scenario: state the defect, how it fails
Preserve backwards compatibility unless the task explicitly authorizes a breaking change.
- Do not weaken security checks, path hardening, sanitization, or generated-skill scanning to make an experiment pass.
## Execution loop
checker and effective budget come from main, not the PR. Keep default CODEOWNERS.
## Security requirements for coding agents
- Never commit real API or admin keys, bearer tokens, webhook secrets, cloud
invoked directly.
Next.js documentation explicitly states: "Treat Server Actions with the same security considerations as public-facing API endpoints, and verify if the user is allowed to perform a mutation
filesystem path, use
`composio.utils.safe_path.secure_join(root, *components)`. For an untrusted
filename, use `secure_basename_join(base, filename, root=root)` so ordinary
extensions remain valid while the write stays anchored
labels, and troubleshooting.
- [LangChain contributing guide](https://docs.langchain.com/oss/python/contributing/overview) — general contribution policy.
## Corridor security analysis
When Corridor's `analyzePlan` tool is available, create a plan and use the tool
Kestra cannot boot in the worktree. The script is idempotent — safe to re-run.
### Security Considerations
- Use tenant isolation for multi-tenant features
- Implement proper authorization with `@HasAnyPermission`
- Handle secrets
pass. If adding runtime logic, include lightweight tests (e.g., Vitest) in the same directory.
## Security & Config Tips
- Use `.env` for local overrides; never commit secrets. Key envs: `FRONTEND_PORT`, `BACKEND
using 8.8.8.8 as DNS server
```javascript
const config = {
performance: { cache: true, timeout: 30000 },
security: { encryption: 'AES-256' }
};
```
### Cards and columns for emphasising information
Example of cards and card groups:
Complete
GitHub did not close.
## Formats
- CHANGELOG: `## [X.Y.Z] - YYYY-MM-DD`, then `### Added|Fixed|Changed|Security`, then `### Thanks` with one line per contributor (first name or @handle, what they did, issue
type references
```
### JSON parsing
Never use `JSON.parse` directly in production code to prevent security risks.
Instead use `parseJSON` or `safeParseJSON` from `@ai-sdk/provider-utils`.
### Type Checking
Always run type checking
both gates but still follow the merge policy above.
- **PR disclosure:** `.github/pull_request_template.md` ends with `## Security Disclosure` and `## Agent Disclosure` sections. Fill both when opening a PR — including PRs authored