Skip to content

docs: add Security & Quality Conventions to copilot-instructions.md - #30

Merged
bmfmancini merged 2 commits into
developfrom
docs/security-quality-conventions
Sep 23, 2026
Merged

bmfmancini merged 2 commits into
developfrom
docs/security-quality-conventions

Conversation

@TheWitness

Copy link
Copy Markdown
Member

Adds a "Security & Quality Conventions" section to .github/copilot-instructions.md, documenting recurring patterns established across the Cacti plugin fleet:

  • No hardcoded third-party hosts (expose as a setting instead)
  • Prepared statements over db_qstr()
  • html_escape_request_var() over html_escape(get_request_var(...))
  • Hardened unserialize() (allow_classes => false)
  • i18n text domain on every translated string
  • The api_plugin_db_table_create()/api_plugin_db_add_column() idempotent table-creation API
  • The standard PHPDoc block shape (description, blank comment, @param, blank comment, @return)

Documentation-only change, no functional/behavioral changes.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Documentation issues must be corrected before approval.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 Low severity

Open (2)
What changed in this PR

Adds security and quality conventions to .github/copilot-instructions.md for future Cacti plugin development.

Changes:

  • Documents secure host, SQL, escaping, serialization, i18n, schema, and PHPDoc practices.
  • Review identified documentation corrections and consistency updates required.
File Summary
.github/​copilot-instructions.md Adds Security & Quality Conventions guidance; corrections are required for serialization, i18n coverage, changelog documentation, and schema-migration consistency.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/copilot-instructions.md Outdated
Comment thread .github/copilot-instructions.md
bmfmancini
bmfmancini previously approved these changes Sep 21, 2026
PHP's unserialize() option is 'allowed_classes' (with the 'ed'), not
'allow_classes' - the latter is silently ignored, so following the prior
wording would not actually disable object instantiation.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Documentation-only changes with no unresolved review issues.

Review effort: Lite
Findings: 1 Low severity

Open (1)
Resolved since last review (1)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Resolve the two documented consistency issues before approval.

Review effort: Lite
Findings: None

Resolved since last review (1)

@bmfmancini bmfmancini left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@bmfmancini
bmfmancini merged commit 116aede into develop Sep 23, 2026
5 checks passed
@bmfmancini
bmfmancini deleted the docs/security-quality-conventions branch September 23, 2026 00:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants