Private early access · free while in early accessWhat works today
The catalog

171 standards you don't have to write.

Packs are maintained sets of engineering standards, written for coding agents and tested against real code. Adopt the ones that fit your stack, then tune each rule for your organization, a team or a repository. The catalog is open source.

§ 01schedule of packs

Open a pack to see each standard: its severity, whether a check backs it, and the stage it should start at.

13packs
171standards
93with a deterministic check; the rest are guidance agents follow
34blockers

What's in the catalog.

Low-noise checks can start at Enforce; anything likely to flag existing code starts earlier. The bar on each row shows how many of its standards a check backs.

P-01Security baselineSecrets, credentials, TLS, and supply-chain basics every repository should follow.OWASP ASVS · SOC 2 · ISO 27001 · PCI DSS · HIPAA12 / 2011
  • SEC-001No private keys in the repositorycheck: regex · starts at Enforceblocker
  • SEC-002No environment files in the repositorycheck: files · starts at Enforceblocker
  • SEC-003No access tokens in codecheck: regex · starts at Enforceblocker
  • SEC-004Do not disable TLS verificationcheck: regex · starts at Adviseblocker
  • SEC-005Commit a dependency lockfilecheck: files · starts at Enforcewarning
  • SEC-006Never log secrets or personal dataguidance for agents · starts at Teachwarning
  • SEC-007No Google API keys in codecheck: regex · starts at Advisewarning
  • SEC-008No Slack webhook URLs in codecheck: regex · starts at Enforceblocker
  • SEC-009No npm access tokens in code or .npmrccheck: regex · starts at Enforceblocker
  • SEC-010No Azure storage or Service Bus keys in connection stringscheck: regex · starts at Enforceblocker
  • SEC-011No SSH keys or key stores in the repositorycheck: files · starts at Enforceblocker
  • SEC-012No hard-coded passwords or secrets in string literalscheck: regex · starts at Advisewarning
  • SEC-013Do not enable SSLv3, TLS 1.0, or TLS 1.1check: regex · starts at Enforcewarning
  • SEC-015Use parameterized queries, never string-built SQLguidance for agents · starts at Teachblocker
  • SEC-016Never deserialize untrusted data with native object serializersguidance for agents · starts at Teachblocker
  • SEC-017Set Secure, HttpOnly, and SameSite on session cookiesguidance for agents · starts at Teachwarning
  • SEC-018Restrict CORS to an allow list of trusted originsguidance for agents · starts at Teachwarning
  • SEC-019Verify JWT signature, algorithm, and expiryguidance for agents · starts at Teachblocker
  • SEC-020Validate destinations before making server-side requests to user-supplied URLsguidance for agents · starts at Teachwarning
  • SEC-021Generate tokens and secrets with a cryptographically secure random generatorguidance for agents · starts at Teachwarning
P-02TypeScript and Node.jsLow-noise conventions for TypeScript and JavaScript codebases.OWASP ASVS · ISO 270019 / 151
  • TS-001No console.log in application codecheck: regex · starts at Advisewarning
  • TS-002No deprecated HTTP and UUID packagescheck: dependencies · starts at Enforcewarning
  • TS-003No eval or new Functioncheck: regex · starts at Enforceblocker
  • TS-004Prefer @ts-expect-error over @ts-ignorecheck: regex · starts at Adviseadvisory
  • TS-005Type and validate at the boundariesguidance for agents · starts at Teachwarning
  • TS-006Await or handle every promiseguidance for agents · starts at Teachwarning
  • TS-007Keep TypeScript strict mode oncheck: regex · starts at Advisewarning
  • TS-008Narrow types instead of asserting themguidance for agents · starts at Teachadvisory
  • TS-009Import Node.js built-ins with the node: prefixcheck: regex · starts at Adviseinfo
  • TS-010Only entry points call process.exitguidance for agents · starts at Teachwarning
  • TS-011No deprecated Buffer() constructorcheck: regex · starts at Enforcewarning
  • TS-012No blocking synchronous I/O on request pathsguidance for agents · starts at Teachwarning
  • TS-013Type caught errors as unknown, not anycheck: regex · starts at Adviseadvisory
  • TS-014No debugger statementscheck: regex · starts at Enforcewarning
  • TS-015Declare the supported Node.js version in package.jsonguidance for agents · starts at Teachadvisory
P-03ReactSecurity, accessibility, and correctness conventions for React applications.OWASP ASVS6 / 121
  • REACT-001Sanitize HTML passed to dangerouslySetInnerHTMLcheck: regex · starts at Advisewarning
  • REACT-002Use stable IDs, not array indexes, as list keyscheck: regex · starts at Adviseadvisory
  • REACT-003Add rel="noopener noreferrer" to target="_blank" linkscheck: regex · starts at Adviseadvisory
  • REACT-004Use refs, not document queries, inside componentscheck: regex · starts at Adviseadvisory
  • REACT-005Follow the Rules of Hooksguidance for agents · starts at Teachwarning
  • REACT-006Give every img an alt attributecheck: regex · starts at Advisewarning
  • REACT-007Use buttons and links for interactive elementsguidance for agents · starts at Teachwarning
  • REACT-008No secrets in client-exposed environment variablescheck: regex · starts at Enforceblocker
  • REACT-009Write function components with hooksguidance for agents · starts at Teachadvisory
  • REACT-010Fetch data through the project's data layerguidance for agents · starts at Teachadvisory
  • REACT-011Do not use effects for derived state or event logicguidance for agents · starts at Teachadvisory
  • REACT-012Keep rendering pure and state immutableguidance for agents · starts at Teachwarning
P-04PythonLow-noise correctness, security, and maintainability conventions for Python codebases.OWASP ASVS11 / 163
  • PY-001No bare except clausescheck: regex · starts at Enforcewarning
  • PY-002No mutable default argumentscheck: regex · starts at Enforcewarning
  • PY-003No print() in application codecheck: regex · starts at Advisewarning
  • PY-004Do not unpickle data you did not producecheck: regex · starts at Advisewarning
  • PY-005Load YAML with yaml.safe_loadcheck: regex · starts at Enforceblocker
  • PY-006Run subprocesses without a shellcheck: regex · starts at Advisewarning
  • PY-007No eval or execcheck: regex · starts at Enforceblocker
  • PY-008No wildcard importscheck: regex · starts at Enforceadvisory
  • PY-009Set a timeout on every requests callcheck: regex · starts at Advisewarning
  • PY-010Use timezone-aware datetimes instead of utcnow()check: regex · starts at Enforcewarning
  • PY-011Never enable Django or Flask debug mode in deployable codecheck: regex · starts at Adviseblocker
  • PY-012Do not use assert for runtime validationguidance for agents · starts at Teachwarning
  • PY-013Type-annotate public functionsguidance for agents · starts at Teachadvisory
  • PY-014Declare project metadata and tool settings in pyproject.tomlguidance for agents · starts at Teachadvisory
  • PY-015Use module loggers with lazy formattingguidance for agents · starts at Teachadvisory
  • PY-016Use the secrets module for security-sensitive randomnessguidance for agents · starts at Teachwarning
P-05Java and Spring BootConventions for Spring Boot services.OWASP ASVS12 / 162
  • JAVA-001Use constructor injectioncheck: regex · starts at Advisewarning
  • JAVA-002Log with the logging frameworkcheck: regex · starts at Advisewarning
  • JAVA-003Controllers must not use repositories directlycheck: regex · starts at Advisewarning
  • JAVA-004Keep business logic out of controllersguidance for agents · starts at Teachwarning
  • JAVA-005Put @Transactional on services, not controllerscheck: regex · starts at Advisewarning
  • JAVA-006Do not put @Transactional on private methodscheck: regex · starts at Enforcewarning
  • JAVA-007Do not build SQL or JPQL by string concatenationcheck: regex · starts at Adviseblocker
  • JAVA-008No literal secrets in Spring configuration filescheck: regex · starts at Adviseblocker
  • JAVA-009Do not expose all Actuator endpoints over HTTPcheck: regex · starts at Advisewarning
  • JAVA-010Justify every CSRF disable in Spring Securitycheck: regex · starts at Advisewarning
  • JAVA-011Use SLF4J placeholders, not string concatenation, in log callscheck: regex · starts at Adviseadvisory
  • JAVA-012Use java.time instead of Date, Calendar, and SimpleDateFormatcheck: regex · starts at Adviseadvisory
  • JAVA-013Do not use Lombok @Data on JPA entitiescheck: regex · starts at Advisewarning
  • JAVA-014Never bind request bodies to JPA entitiesguidance for agents · starts at Teachwarning
  • JAVA-015Validate request DTOs with Bean Validation and @Validguidance for agents · starts at Teachwarning
  • JAVA-016Handle exceptions centrally; never swallow themguidance for agents · starts at Teachwarning
P-06GoError handling, concurrency, HTTP, and security conventions for Go services and libraries.OWASP ASVS8 / 131
  • GO-001Handle every returned errorguidance for agents · starts at Teachwarning
  • GO-002Wrap errors with %w, not %vcheck: regex · starts at Adviseadvisory
  • GO-003Do not panic in library codecheck: regex · starts at Adviseadvisory
  • GO-004Pass context.Context as the first parameterguidance for agents · starts at Teachwarning
  • GO-005Give every goroutine a way to stopguidance for agents · starts at Teachwarning
  • GO-006Do not make HTTP calls without a timeoutcheck: regex · starts at Advisewarning
  • GO-007Set timeouts on HTTP serverscheck: regex · starts at Advisewarning
  • GO-008Use query placeholders, not fmt.Sprintf, to build SQLcheck: regex · starts at Adviseblocker
  • GO-009Use crypto/rand for security-sensitive random valuescheck: regex · starts at Advisewarning
  • GO-010No fmt.Print in library codecheck: regex · starts at Adviseadvisory
  • GO-011No unmaintained JWT and UUID modulescheck: dependencies · starts at Enforcewarning
  • GO-012Close resources with defer right after acquiring themguidance for agents · starts at Teachwarning
  • GO-013Run gofmt, go vet, and tests with the race detector in CIguidance for agents · starts at Teachadvisory
P-07HTTP API designError handling, status codes, pagination, idempotency, versioning, and access control for HTTP APIs, in any language.OWASP ASVS1 / 122
  • HTTP-001Return one documented error shape and never expose internalscheck: regex · starts at Advisewarning
  • HTTP-002Use the status code that matches the outcomeguidance for agents · starts at Teachwarning
  • HTTP-003Paginate every list endpoint with a server-enforced maximum page sizeguidance for agents · starts at Teachwarning
  • HTTP-004Make side-effecting POST requests safe to retry with idempotency keysguidance for agents · starts at Teachwarning
  • HTTP-005Do not make breaking changes to a published API versionguidance for agents · starts at Teachblocker
  • HTTP-006Validate every request against a schema and never bind it straight to a modelguidance for agents · starts at Teachwarning
  • HTTP-007Authenticate and authorize every endpoint, denying by defaultguidance for agents · starts at Teachblocker
  • HTTP-008Rate limit authentication and expensive endpointsguidance for agents · starts at Teachwarning
  • HTTP-009Use unambiguous formats for timestamps and moneyguidance for agents · starts at Teachadvisory
  • HTTP-010Expose opaque public identifiers, not database keysguidance for agents · starts at Teachadvisory
  • HTTP-011Update the API description in the same change as the APIguidance for agents · starts at Teachwarning
  • HTTP-012Follow the API's existing naming and resource conventionsguidance for agents · starts at Teachadvisory
P-08DockerSecure, reproducible, and lean container images built from Dockerfiles.8 / 12–
  • DOCKER-001Run the final image as a non-root usercheck: regex · starts at Advisewarning
  • DOCKER-002Pin base images to a version tag or digestcheck: regex · starts at Enforcewarning
  • DOCKER-003Use COPY for local files, not ADDcheck: regex · starts at Adviseadvisory
  • DOCKER-004Do not pipe downloaded scripts into a shellcheck: regex · starts at Advisewarning
  • DOCKER-005Do not pass secrets through ENV or ARGcheck: regex · starts at Advisewarning
  • DOCKER-006Run apt-get update and install in the same RUNcheck: regex · starts at Enforcewarning
  • DOCKER-007Install apt packages with --no-install-recommendscheck: regex · starts at Adviseadvisory
  • DOCKER-008Use the exec form for CMD and ENTRYPOINTcheck: regex · starts at Adviseadvisory
  • DOCKER-009Keep a .dockerignore next to every build contextguidance for agents · starts at Teachadvisory
  • DOCKER-010Use multi-stage builds to keep toolchains out of runtime imagesguidance for agents · starts at Teachadvisory
  • DOCKER-011Order Dockerfile steps for layer cachingguidance for agents · starts at Teachinfo
  • DOCKER-012Get OS patches by updating the base imageguidance for agents · starts at Teachadvisory
P-09KubernetesSecure and reliable Kubernetes manifests, aligned with the Pod Security Standards.8 / 123
  • K8S-001No privileged containerscheck: regex · starts at Enforceblocker
  • K8S-002Do not share the host network, PID, or IPC namespacecheck: regex · starts at Adviseblocker
  • K8S-003Set allowPrivilegeEscalation to falsecheck: regex · starts at Advisewarning
  • K8S-004Require runAsNonRootcheck: regex · starts at Advisewarning
  • K8S-005Harden pod security contexts to the restricted profileguidance for agents · starts at Teachwarning
  • K8S-006Set resource requests for every containercheck: regex · starts at Advisewarning
  • K8S-007Pin container images to a version tag or digestcheck: regex · starts at Advisewarning
  • K8S-008Do not commit Secret manifests with valuescheck: regex · starts at Adviseblocker
  • K8S-009Give long-running containers readiness and liveness probesguidance for agents · starts at Teachwarning
  • K8S-010Restrict pod traffic with NetworkPoliciesguidance for agents · starts at Teachadvisory
  • K8S-011Deploy workloads to a dedicated namespace, not defaultguidance for agents · starts at Teachadvisory
  • K8S-012No wildcard RBAC rules or cluster-admin bindingscheck: regex · starts at Advisewarning
P-10TerraformCredentials, state, supply-chain pinning, and network exposure rules for Terraform code.OWASP ASVS · SOC 2 · ISO 27001 · HIPAA7 / 124
  • TF-001No hard-coded credentials in Terraformcheck: regex · starts at Adviseblocker
  • TF-002Constrain Terraform and provider versionsguidance for agents · starts at Teachwarning
  • TF-003Commit the Terraform dependency lock filecheck: files · starts at Advisewarning
  • TF-004Pin module sources to a versioncheck: regex · starts at Enforcewarning
  • TF-005Do not open SSH or RDP to the internetcheck: regex · starts at Enforceblocker
  • TF-006Do not make storage buckets publiccheck: regex · starts at Adviseblocker
  • TF-007No Terraform state files in the repositorycheck: files · starts at Enforceblocker
  • TF-008Do not commit the .terraform directorycheck: files · starts at Enforcewarning
  • TF-009Keep secrets out of tfvars and mark secret variables sensitiveguidance for agents · starts at Teachwarning
  • TF-010Use a remote backend with state lockingguidance for agents · starts at Teachwarning
  • TF-011Enable encryption at rest for data storesguidance for agents · starts at Teachwarning
  • TF-012Give variables and outputs a type and descriptionguidance for agents · starts at Teachinfo
P-11GitHub ActionsSupply-chain pinning, token permissions, and injection safety for GitHub Actions workflows.6 / 102
  • GHA-001Pin third-party actions to a full commit SHAcheck: regex · starts at Advisewarning
  • GHA-002Declare minimal token permissions in every workflowcheck: regex · starts at Advisewarning
  • GHA-003Do not interpolate untrusted event data into scriptscheck: regex · starts at Enforceblocker
  • GHA-004Do not check out pull request code in pull_request_target workflowscheck: regex · starts at Adviseblocker
  • GHA-005Do not pipe downloaded scripts into a shell in workflowscheck: regex · starts at Advisewarning
  • GHA-006Authenticate to cloud providers with OIDC, not long-lived keyscheck: regex · starts at Advisewarning
  • GHA-007Pass secrets to steps through env and never print themguidance for agents · starts at Teachwarning
  • GHA-008Do not persist checkout credentials unless a later step pushesguidance for agents · starts at Teachadvisory
  • GHA-009Bound job runtime and cancel superseded runsguidance for agents · starts at Teachadvisory
  • GHA-010Deploy through protected environmentsguidance for agents · starts at Teachadvisory
P-12TestingKeep test suites trustworthy, deterministic, and honest, across JavaScript, Python, Java, Go, and Ruby.4 / 111
  • TEST-001Do not commit focused testscheck: regex · starts at Enforceblocker
  • TEST-002Every skipped test states whycheck: regex · starts at Advisewarning
  • TEST-003Unit tests do not call real external servicesguidance for agents · starts at Teachwarning
  • TEST-004Fix bugs with a regression test that fails firstguidance for agents · starts at Teachwarning
  • TEST-005Wait for conditions, not fixed sleeps, in testscheck: regex · starts at Advisewarning
  • TEST-006Control time, randomness, and shared state in testsguidance for agents · starts at Teachwarning
  • TEST-007Name tests after the behavior they verifyguidance for agents · starts at Teachadvisory
  • TEST-008Review snapshot and golden-file changes; never update them blindlyguidance for agents · starts at Teachwarning
  • TEST-009Test new and changed behavior, not coverage numbersguidance for agents · starts at Teachadvisory
  • TEST-010Mock at the system boundary and assert on outcomesguidance for agents · starts at Teachadvisory
  • TEST-011Do not commit test results or coverage outputcheck: files · starts at Enforcewarning
P-13AI coding agent hygieneHow AI coding agents should work in a repository - scoped changes, honest verification, no weakened tests, and no surprises.1 / 103
  • AGENT-001Regenerate generated files; never edit them by handguidance for agents · starts at Teachwarning
  • AGENT-002Justify every new dependency and prefer what the project already usesguidance for agents · starts at Teachwarning
  • AGENT-003Keep changes scoped to the taskguidance for agents · starts at Teachwarning
  • AGENT-004Run the project's checks before declaring the work doneguidance for agents · starts at Teachwarning
  • AGENT-005Never weaken tests or checks to get a green buildguidance for agents · starts at Teachblocker
  • AGENT-006Ask before destructive or irreversible operationsguidance for agents · starts at Teachblocker
  • AGENT-007Follow existing patterns before introducing new onesguidance for agents · starts at Teachwarning
  • AGENT-008Update docs, examples, and the changelog when behavior changesguidance for agents · starts at Teachadvisory
  • AGENT-009State assumptions, open questions, and unverified partsguidance for agents · starts at Teachwarning
  • AGENT-010No merge conflict markers or merge leftoverscheck: regex, files · starts at Enforceblocker

Source: groundrule:packs, snapshot of the open-source catalog. Pack references read groundrule:packs/<id>.

§ 02anatomy

A standard is a YAML file in an open format. This one is real.

More than a lint rule.

  • Intent and requirementWhy the rule exists, and what to do, in plain words an agent can act on.
  • A check, where one is honestPatterns, required or forbidden files, forbidden dependencies, files that change together, or Semgrep. No check where only judgment works.
  • Known false positivesWhere each rule misfires and how to scope it out, with a noise rating.
  • A recommended starting stageSo adopting a pack never turns CI red on day one.

Every field of the rule format

security-baseline/standards/SEC-001.yamlfig. 02
metadata:
  id: SEC-001
  title: No private keys in the repository
  type: prohibition
spec:
  severity: blocker
  intent: A committed private key must be treated as leaked,
    even after it is deleted from history.
  requirement: Never commit private keys. Load them at runtime
    from a secret manager or the environment.
  checks:
    - evaluator: regex
      pattern: "-----BEGIN (?:RSA |EC |…)?PRIVATE KEY…-----"
      exclude: ["**/testdata/**", "**/fixtures/**"]
  references: [CWE-321, CWE-798]
  compliance:
    - { framework: soc2, controls: [CC6.1] }
    - { framework: iso-27001, controls: ["8.24", "5.17"] }
  quality: { noise: low }
  rollout: { recommendedStage: enforce }
§ 03 · sign-off · Private early access, free while in early access

Start from the packs that fit your stack.

Onboarding picks them for you from four questions. Every rule starts at a stage where it can't block anyone, and you see what it would catch before it can.