efficiency), input validation at trust boundaries, error handling that prevents data loss, security, accessibility, the calibration real hardware needs (the platform is never the spec ideal, a clock drifts
Threshold
Only comment when you are **>85% confident** the issue is a real bug, security vulnerability, or logic error. If you are unsure, do not comment. Silence is better than
Guidelines
When reviewing pull requests:
- Only comment on semantically meaningful issues: bugs, incorrect logic, security problems, or API contract violations.
- Skip style, formatting, naming, and whitespace observations unless they cause
text should be called out.
4. For user-facing, release, dependency, workflow, or security-sensitive changes, prefer blocking feedback over optional suggestions.
5. Focus on correctness, safety, and whether
full|wenyan-ultra
Stop: "stop caveman" or "normal mode"
Auto-Clarity: drop caveman for security warnings, irreversible actions, user confused. Resume after.
Boundaries: code/commits/PRs written normal
Lucide React (`lucide-react`). Do NOT add new icon packages.
- Static assets: `frontend/assets/images/`.
## Security
- No API keys/secrets in client-side code.
- Backend: parameterized queries only, never concatenate user input into
date by running generate-docs and checking git diff
4. **code-scanning.yml** - CodeQL security analysis for Go and GitHub Actions
5. **license-check.yml** - Runs `script/licenses-check` to validate compliance
6. **docker-publish.yml** - Publishes container
Copilot instructions for this repository
## Flag likely CVE / security-vulnerability fixes
Commits on `master` are automatically synced to the public `mongodb/mongo` repository. A security
fix that lands on `master` before
between builds when possible
- **Yarn Cache**: Dependencies are cached globally to speed up installs
## Security Notes
- Never commit secrets to source code
- Use environment variables for configuration
- Default admin token
integration tests for API endpoints
- Maintain test coverage above 70%
- Mock external dependencies appropriately
## Security Considerations
- Never commit secrets or API keys
- Use environment variables for configuration
- Implement proper authentication
system (3.14+)
- Google Test for unit testing
- Support for multiple compilers (MSVC, GCC, Clang)
## Security Considerations
- Bounds checking is a core principle - enforce it consistently
- Design for safety while minimizing
packages or modules that change the repo structure
- Cross-cutting changes spanning 3+ packages
- Security model changes (identity, trust, policy engine)
- Breaking API changes to public interfaces
- New framework integrations
keeps maintenance overhead low and makes it easier to pull in new versions and security updates from upstream.
While AZL derives from Fedora, it is also an enterprise focused distro
pull requests:
- Only leave comments for critical, major, or high-severity issues: logic
bugs, security vulnerabilities, data loss or corruption, race conditions,
and breaking API changes.
- Do NOT comment