- TypeScript + Fastify skeleton under project/ (src/modules, shared, infrastructure, app) - scripts/check-module-boundaries.mjs enforcing module public-API rules (tested with fixtures) - GET /health endpoint, error envelope without stack leakage - specs/F-001-scaffold (SPEC/DESIGN/TASKS/TESTS), spec/tech.md dependency justification - 30-ticket MercadoDeVida roadmap in backlog/features.json, spec/roadmap.md - All gates approved: reviewer, security, qa; verify.sh green
501 B
501 B
Security Policy
Gate de seguridad (obligatorio)
Cada feature debe tener work/artifacts/<feature_id>/security.json con:
verdict: APPROVED | CHANGES_REQUESTEDchecks: secretos, dependencias, SAST básico, validación de inputsfindings: lista de hallazgos con severidad
Reglas
- Si hay hallazgos críticos/altos sin mitigación:
CHANGES_REQUESTED. - No se permite exponer credenciales ni secretos en repo/chat.
- Dependencias nuevas requieren justificación en
spec/tech.md.