Skip to content

docs: add Security & Quality Conventions to copilot-instructions.md - #22

Merged
bmfmancini merged 2 commits into
mainfrom
docs/security-quality-conventions
Sep 23, 2026
Merged

bmfmancini merged 2 commits into
mainfrom
docs/security-quality-conventions

Conversation

@TheWitness

Copy link
Copy Markdown
Member

Adds a "Security & Quality Conventions" section to .github/copilot-instructions.md, documenting recurring patterns established across the Cacti plugin fleet:

  • No hardcoded third-party hosts (expose as a setting instead)
  • Prepared statements over db_qstr()
  • html_escape_request_var() over html_escape(get_request_var(...))
  • Hardened unserialize() (allow_classes => false)
  • i18n text domain on every translated string
  • The api_plugin_db_table_create()/api_plugin_db_add_column() idempotent table-creation API
  • The standard PHPDoc block shape (description, blank comment, @param, blank comment, @return)

Documentation-only change, no functional/behavioral changes.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Documentation-only update with low risk; suggested edits are minor clarity/style nits.

Review effort: Lite
Findings: 2 Low severity

Open (2)
What changed in this PR

Adds a “Security & Quality Conventions” section to the repository’s Copilot instructions, capturing recurring secure/maintainable implementation patterns used across the Cacti plugin ecosystem.

Changes:

  • Documented security conventions (no hardcoded third-party hosts, prepared statements, hardened unserialize(), safer request escaping).
  • Documented consistency conventions (i18n text domain usage, idempotent plugin DB table helpers, standard PHPDoc block structure).
File Description
.github/​copilot-instructions.md Adds a new “Security & Quality Conventions” section to standardize secure/consistent coding guidance for contributors and Copilot-generated code.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/copilot-instructions.md
Comment thread .github/copilot-instructions.md Outdated
bmfmancini
bmfmancini previously approved these changes Sep 21, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Documentation-only changes are clear, consistent with surrounding guidance, and introduce no behavioral risk.

Review effort: Lite
Findings: None

Resolved since last review (2)

@bmfmancini bmfmancini left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@bmfmancini
bmfmancini merged commit dc20e33 into main Sep 23, 2026
4 checks passed
@TheWitness
TheWitness deleted the docs/security-quality-conventions branch September 25, 2026 07:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants