Prefer simple conditionals over nested ternary operators
- Group related code together and separate concerns
### Security
- Add `rel="noopener"` when using `target="_blank"` on links
- Avoid `dangerouslySetInnerHTML` unless absolutely necessary
passwordless mode), the DEK is stored in plaintext — suitable for PaaS deploys where volume security is the trust boundary. Login uses email+password. The first user to register becomes
user explicitly asks.
Test processes use isolated Application Support storage.
## Top Level Rules
- Security first
- Maintainability
- Scalability
- Clean Code
- Clean Architecture
- Best Practices
- No Hacky Solutions
- Do not present assumptions
rather than `/tmp` — `bin/` is gitignored and within the project's trusted directory.
macOS security may block execution of binaries built outside the project tree.
## Project Structure
- `cmd/stripe/main.go` - Entry point
Manually update skeleton's CLI version and release another cli-hydrogen cycle
- **No** → Done
## Security concerns
All content inside of `secrets.ejson` is sensitive and must NEVER be exposed. We have
README.
## Development Guidelines
### Quality gates
Three layers: pre-commit (under 5s, Groq/Gemini complexity plus security, blocks on
complexity above 8 or a security finding), the PR gate
`bash scripts/pr/pre_pr_check.sh
Unit tests for utilities
- Integration tests for APIs
- E2E tests for critical flows
### 4. Security
- No hardcoded secrets
- Environment variables for sensitive data
- Validate all user inputs
- Parameterized queries only
flight features (profiler, pgbackrest, etc.) |
| `.claude/skills/pg-security-release-analysis/` | Skill for triaging upstream PG quarterly security releases into a CVE/impact catalog — see below |
## Building and testing
Exact commands verified against `nix/docs/build-postgres.md`,
`nix/docs/development-workflow.md
tests for new logic, both UI and API.
**Before committing:**
- Run formatter, linter, and security scans.
- Ensure commit messages explain *why*, not just *what*.
### Error Handling
- Fail fast with descriptive
real root cause.
- Reject fixes that only patch symptoms.
- Reject changes that damage architecture, security, performance, maintainability, or type safety.
- Prefer minimal correct fixes over large unnecessary rewrites.
- Explain
that converts Terraform code into professional cloud architecture diagrams. It runs 100% client-side, securely parses Terraform plans, and generates visual representations of cloud infrastructure without requiring access to cloud
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.