frontend on `:4200`
- CI automatically runs frontend tests, backend tests, formatting checks, and security scans
- Deployments to production trigger automatically when CI passes on the `main` branch
## 3) Key Repository
thread.
- **Errors:** typed and explicit; map errors at layer boundaries; no silent `try?` swallowing.
- **Security:** follow OWASP MASVS and `standards/security_standards.md`. Never hardcode or
log secrets. Store credentials in the platform
Register it in `workflows::get_workflow()` match arm
3. Declare `pub mod ;` in `workflows/mod.rs`
### Security invariants — do not relax
- **Terminal tool** (`tools/terminal.rs`): validate every command against `ALLOWED_COMMANDS = ["cargo
fixes, always write a test that reproduces the bug before writing the fix.
## Security
Never hardcode secrets, API keys, or passwords in source code. Use environment variables loaded from
mode preferred)
- Use pytest for testing with high coverage (80% minimum)
- Use bandit for security scanning
## Code Style
- Write clean, readable, maintainable code
- Prefer explicit over implicit
- Keep functions small
describing what happens after deploy, use "typically" since pickup timing depends on the agent.
### Security (block if violated)
- No secrets, credentials, or tokens in committed code. Flag any hardcoded paths
AZIHSM SDK, its simulator, and its OpenSSL Provider. The project focuses on creating secure, high-performance APIs.
## Technology Stack
- **Language**: For AZIHSM SDK and simulator: Rust (using Cargo build system
cross-references within the crate
- RFC section references use `§N.N` format (e.g., `§4.2.1`)
## Security audit checklist (for new code)
When adding new types or serde impls, verify:
1. ☐ Zero
thorough; a clean diff with zero findings is a valid, expected outcome. Prioritize CRITICAL security issues (hardcoded secrets, injection, auth bypass), then HIGH quality issues (unhandled errors, deep nesting, missing
under `## [Unreleased]` in `CHANGELOG.md`. Keep-a-Changelog 1.1.0 ordering: Added, Changed, Deprecated, Removed, Fixed, Security. Promote to a dated section on tag push.
4. **Green gate plus TDD.** `dart format
regressions.
- Run the full verification checklist (build check, typescript typecheck, ESLint, test suite, and security scans) continuously at every coding milestone.
- Use `rtk proxy` to inspect all compilation details (when
strings, code blocks,
input validation at trust boundaries, error handling that prevents data loss,
security measures, accessibility basics, anything asked for in full. Written
normally, never compressed: code, comments, commit