The CamelHive Standard · version history
Standard, as of v3.25.0
155 of 203 rules active in this version.
- CH-SNAP-001Repo can be cloned and runs todaynot measured by the corpus
- CH-SNAP-002MVP contains 1–3 real functional flowscorpus can measure detection
- CH-SNAP-003Tech stack clearly identifiablecorpus can measure false positives only
- CH-SNAP-004Backend exists (not mock APIs)corpus can measure detection
- CH-SNAP-005Data persistence exists and is realcorpus can measure detection
- CH-SNAP-006Deployment pipeline exists or is trivial to addcorpus can measure detection
- CH-SNAP-007No secrets hardcoded in repoDeprecatedcorpus can measure detection
- CH-ARCH-001Clear separation of concernscorpus can measure detection
- CH-ARCH-002No circular dependenciescorpus can measure detection
- CH-ARCH-003Predictable folder structureDeprecatednot measured by the corpus
- CH-ARCH-004Controller → service → repository pattern OR equivalentcorpus can measure false positives only
- CH-ARCH-005Business logic not mixed with controllersDeprecatednot measured by the corpus
- CH-ARCH-006Boundaries respected between modulescorpus can measure detection
- CH-DATA-001Data normalized (typically 3NF) to prevent dangerous redundancycorpus can measure detection
- CH-DATA-002Strict Foreign Key constraints enforced at the database levelcorpus can measure detection
- CH-DATA-003Schema migrations governed by code (Prisma, TypeORM, Alembic, etc.)corpus can measure detection
- CH-DATA-004ACID transactions used for multi-table mutations to prevent race conditionscorpus can measure detection
- CH-CODE-001Consistent naming conventionsDeprecatednot measured by the corpus
- CH-CODE-002No duplicate logic across modulesDeprecatednot measured by the corpus
- CH-CODE-003File size manageable (<300 lines ideally)corpus can measure detection
- CH-CODE-004Dead/commented code removedDeprecatednot measured by the corpus
- CH-CODE-005Linting + formatting enforcedDeprecatednot measured by the corpus
- CH-TEST-001Critical path test coverage existscorpus can measure false positives only
- CH-TEST-002CI executes tests on every pushcorpus can measure detection
- CH-TEST-003No failing testsDeprecatednot measured by the corpus
- CH-LEGL-001Sensitive data handled correctly (PII encryption, safe storage)Deprecatednot measured by the corpus
- CH-LEGL-002GDPR/CCPA relevant exposure identifiedDeprecatednot measured by the corpus
- CH-LEGL-003Safe storage of personal data (no plaintext passwords)Deprecatednot measured by the corpus
- CH-LEGL-004Dependency licenses verifiedDeprecatednot measured by the corpus
- CH-LEGL-005API Terms of Service not violatedDeprecatednot measured by the corpus
- CH-SEC-001All input validated/sanitizedcorpus can measure detection
- CH-SEC-002IDs/email/username validated on backendcorpus can measure detection
- CH-SEC-003Strict typing/schema validation at the boundary (Zod, Joi, class-validator)corpus can measure detection
- CH-SEC-004Passwords hashed using bcrypt/scrypt/argon2corpus can measure detection
- CH-SEC-005JWT tokens validated properlycorpus can measure detection
- CH-SEC-006Access tokens not stored in localStorage (unless secure)corpus can measure detection
- CH-SEC-007Role-based access control implementedcorpus can measure detection
- CH-SEC-008No secrets committed to repocorpus can measure detection
- CH-SEC-009Environment variables correctly configuredcorpus can measure detection
- CH-SEC-010Secret rotation procedure existsnot measured by the corpus
- CH-SEC-011Rate limiting applied to sensitive endpointscorpus can measure detection
- CH-SEC-012CORS strict (no wildcard)corpus can measure detection
- CH-SEC-013Errors do not leak stack tracescorpus can measure detection
- CH-SEC-014No packages with critical vulnerabilitiescorpus can measure detection
- CH-SCAL-001No blocking operations on main threadDeprecatednot measured by the corpus
- CH-SCAL-002Async tasks offloaded to queues/workersDeprecatednot measured by the corpus
- CH-SCAL-003Caching strategy implementedDeprecatednot measured by the corpus
- CH-SCAL-004Indexes validated on frequently queried columnsDeprecatednot measured by the corpus
- CH-SCAL-005No N+1 queries in ORM fetch logiccorpus can measure false positives only
- CH-SCAL-006Database connection pooling implemented (e.g., PgBouncer, RDS Proxy)Deprecatednot measured by the corpus
- CH-SCAL-007Soft deletes used instead of hard deletes for critical recordsDeprecatednot measured by the corpus
- CH-SCAL-008Autoscaling enabled (if applicable)Deprecatednot measured by the corpus
- CH-SCAL-009RDS size appropriateDeprecatednot measured by the corpus
- CH-SCAL-010No unlimited log retentionDeprecatednot measured by the corpus
- CH-SCAL-011Assets served via CDNDeprecatednot measured by the corpus
- CH-SCAL-012Bundles reasonably sizedDeprecatednot measured by the corpus
- CH-RELI-001Automated DB backups configuredDeprecatednot measured by the corpus
- CH-RELI-002Backup restoration testedDeprecatednot measured by the corpus
- CH-RELI-003Versioning enabled for critical S3 bucketsnot measured by the corpus
- CH-RELI-004Logs structured in JSONDeprecatednot measured by the corpus
- CH-RELI-005Metrics for CPU/memory/latency existDeprecatednot measured by the corpus
- CH-RELI-006Alerts configured for critical pathsDeprecatednot measured by the corpus
- CH-RELI-007Blue/Green or Rolling deploys implementedDeprecatednot measured by the corpus
- CH-RELI-008Zero-downtime migrationsDeprecatednot measured by the corpus
- CH-RELI-009Health checks implementedDeprecatednot measured by the corpus
- CH-COST-001AWS resources right-sizedDeprecatednot measured by the corpus
- CH-COST-002Log retention cappedDeprecatednot measured by the corpus
- CH-COST-003No idle expensive servicesDeprecatednot measured by the corpus
- CH-COST-004Caching reduces DB loadnot measured by the corpus
- CH-GOVN-001All AI-generated code reviewed by humannot measured by the corpus
- CH-GOVN-002AI does not modify architecture boundariesDeprecatednot measured by the corpus
- CH-GOVN-003Folder structure stays stableDeprecatednot measured by the corpus
- CH-GOVN-004API contract not altered without human approvalDeprecatednot measured by the corpus
- CH-GOVN-005Human-written rationale for major decisionsDeprecatednot measured by the corpus
- CH-MANT-001C4 diagrams includedDeprecatednot measured by the corpus
- CH-MANT-002README with full setup instructionsDeprecatednot measured by the corpus
- CH-MANT-003Dev environment reproducible via DockerDeprecatednot measured by the corpus
- CH-MANT-004CI/CD pipeline documentedDeprecatednot measured by the corpus
- CH-MANT-005Coding style guide availablecorpus can measure detection
- CH-MANT-006Onboarding in <1 hour possibleDeprecatednot measured by the corpus
- CH-API-001RESTful conventions followed consistently (or GraphQL schema well-structured)corpus can measure false positives only
- CH-API-002API versioning strategy defined (/v1/, headers, or explicit)corpus can measure false positives only
- CH-API-003HTTP status codes used correctly (401 vs 403, 400 vs 422, etc.)corpus can measure false positives only
- CH-API-004API contracts documented (OpenAPI / Swagger or equivalent)corpus can measure false positives only
- CH-API-005No breaking changes introduced without version bumpcorpus can measure detection
- CH-API-006Pagination implemented on list endpointscorpus can measure detection
- CH-API-007Consistent error response shape across all endpointscorpus can measure false positives only
- CH-PDAT-001Sensitive data handled correctly (PII encryption, safe storage)corpus can measure detection
- CH-PDAT-002Safe storage of personal data (no plaintext passwords or unencrypted PII)corpus can measure detection
- CH-PDAT-003Cookie policy present and accurate if cookies are usedcorpus can measure detection
- CH-PDAT-004Privacy Policy published and accessiblecorpus can measure detection
- CH-PDAT-005Terms and Conditions published and accessiblecorpus can measure detection
- CH-PDAT-006Dependency licenses verified (no GPL-contaminated deps in commercial product)corpus can measure detection
- CH-PDAT-007Explicit user consent collected before processing non-essential datacorpus can measure detection
- CH-PDAT-008GDPR/CCPA exposure is appropriate for the actual markets and user types this product targetsnot measured by the corpus
- CH-PDAT-009Data retention, deletion rights, and processing purposes are appropriate for the business modelnot measured by the corpus
- CH-PDAT-010Third-party data processors and API ToS exposure match actual usagenot measured by the corpus
- CH-INFR-001No unlimited log retention (retention policy set)not measured by the corpus
- CH-INFR-002Static assets served via CDNnot measured by the corpus
- CH-INFR-003Infrastructure complexity and cost is appropriate for the current tractionnot measured by the corpus
- CH-COST-005Log retention capped at a reasonable window (30-90 days typically)not measured by the corpus
- CH-COST-006Cost alerts configured in cloud provider (billing alarm at threshold)not measured by the corpus
- CH-COST-007Cloud resources are right-sized for actual current loadnot measured by the corpus
- CH-COST-008No idle or forgotten expensive services runningnot measured by the corpus
- CH-COST-009Monthly infrastructure cost is known, tracked, and acceptable for the current stagenot measured by the corpus
- CH-GOVN-006All AI-generated code passes the same linting, testing, and review standards as human codenot measured by the corpus
- CH-GOVN-007AI does not autonomously modify architecture boundaries or module contractsnot measured by the corpus
- CH-GOVN-008Naming conventions are consistent even across AI-generated sectionsDeprecatednot measured by the corpus
- CH-GOVN-009No structural inconsistencies between AI-generated and human-written modulesDeprecatednot measured by the corpus
- CH-GOVN-010Folder structure and module boundaries remain stable across AI-assisted iterationsnot measured by the corpus
- CH-GOVN-011API contracts are versioned and not silently alterednot measured by the corpus
- CH-GOVN-012C4 architecture diagrams present (Context, Container, Component levels minimum)corpus can measure detection
- CH-GOVN-013README with full local setup instructions — works without tribal knowledgecorpus can measure detection
- CH-GOVN-014Dev environment reproducible via Docker or equivalentnot measured by the corpus
- CH-GOVN-015CI/CD pipeline documented and understandablecorpus can measure detection
- CH-GOVN-016Major architectural decisions have human-written rationale (ADRs or equivalent)not measured by the corpus
- CH-GOVN-017The team can maintain what was built — no single point of knowledge or bus factor risknot measured by the corpus
- CH-RELI-010Automated DB backups configured and verifiednot measured by the corpus
- CH-RELI-011Versioning enabled for critical S3 bucketsDeprecatednot measured by the corpus
- CH-RELI-012Backup restoration has been actually tested — not just configurednot measured by the corpus
- CH-RELI-013Recovery time objective (RTO) and recovery point objective (RPO) are defined and acceptablenot measured by the corpus
- CH-RELI-014Logs structured in JSON with consistent fields (timestamp, level, traceId)corpus can measure detection
- CH-RELI-015Metrics for CPU, memory, latency, and error rate availablenot measured by the corpus
- CH-RELI-016Alerts configured for critical failure paths (downtime, high error rate, latency spike)not measured by the corpus
- CH-RELI-017Uptime monitoring in place (external ping, not just internal health checks)not measured by the corpus
- CH-RELI-018Blue/Green or Rolling deploys implemented — no big-bang deploymentsnot measured by the corpus
- CH-RELI-019Zero-downtime database migrations validatedcorpus can measure detection
- CH-RELI-020Health check endpoints implemented and wired to load balancercorpus can measure detection
- CH-RELI-021Rollback procedure documented and testednot measured by the corpus
- CH-SCAL-013No blocking synchronous operations on the main threadcorpus can measure detection
- CH-SCAL-014Heavy or long-running tasks offloaded to queues or background workerscorpus can measure detection
- CH-SCAL-015Caching strategy implemented for expensive or repeated operationscorpus can measure detection
- CH-SCAL-016External API calls have timeout and retry logiccorpus can measure false positives only
- CH-SCAL-017Indexes validated on all frequently queried columnscorpus can measure false positives only
- CH-SCAL-018No N+1 queries in ORM fetch logicDeprecatednot measured by the corpus
- CH-SCAL-019Database connection pooling implemented (PgBouncer, RDS Proxy, or ORM-level)corpus can measure detection
- CH-SCAL-020Query performance validated for the largest expected data setsnot measured by the corpus
- CH-SCAL-021Read replicas or caching considered for read-heavy workloadsnot measured by the corpus
- CH-SEC-015Prevencion de SQL injection verificada (queries parametrizadas o acceso solo por ORM)corpus can measure detection
- CH-SEC-016Validacion de archivos subidos por el usuario, si aplica (tipo, tamano, MIME)corpus can measure detection
- CH-SEC-017Endpoints de autenticacion protegidos contra fuerza bruta (rate limiting + lockout)corpus can measure detection
- CH-SEC-018Flujo de refresh de tokens implementado correctamente, sin access tokens de larga vidacorpus can measure detection
- CH-SEC-019El flujo de reset de password usa tokens de un solo uso y con expiracioncorpus can measure detection
- CH-SEC-020Secretos gestionados via vault o secret manager (no solo variables de entorno planas)corpus can measure detection
- CH-SEC-021Headers de seguridad configurados (Helmet o equivalente): CSP, HSTS, X-Frame-Optionscorpus can measure detection
- CH-SEC-022HTTPS forzado en produccion, sin fallback a HTTPcorpus can measure detection
- CH-SEC-023Dependencias actualizadas dentro de un rango razonablenot measured by the corpus
- CH-SEC-024Auditoria de dependencias automatizada en el pipeline de CIcorpus can measure detection
- CH-SEC-025El sistema no se entrega con credenciales por defecto que funcionen en produccionnot measured by the corpus
- CH-ARCH-007Predictable and consistent folder structurecorpus can measure detection
- CH-ARCH-008Business logic not mixed with controllers or route handlerscorpus can measure false positives only
- CH-ARCH-009No God objects or God services handling unrelated responsibilitiescorpus can measure false positives only
- CH-ARCH-010Shared utilities isolated in a common/utils layercorpus can measure false positives only
- CH-ARCH-011Architecture complexity is appropriate for the product stage — no over-engineeringcorpus can measure detection
- CH-DATA-005Soft deletes used for critical records instead of hard deletescorpus can measure false positives only
- CH-DATA-006Timestamps (created_at, updated_at) present on all critical entitiescorpus can measure false positives only
- CH-DATA-007No JSON blobs used as substitute for proper relational modelingcorpus can measure false positives only
- CH-DATA-008Data model reflects the real business domain — not a misunderstood version of itnot measured by the corpus
- CH-CODE-006Consistent naming conventions (camelCase, snake_case — pick one)corpus can measure false positives only
- CH-CODE-007No duplicate logic across modules (DRY principle respected)corpus can measure false positives only
- CH-CODE-008Dead or commented-out code removedcorpus can measure false positives only
- CH-CODE-009Linting + formatting enforced via config (ESLint, Prettier, etc.)corpus can measure false positives only
- CH-CODE-010No console.log or debug statements left in production codecorpus can measure false positives only
- CH-CODE-011Magic numbers and strings replaced with named constantscorpus can measure false positives only
- CH-TEST-004No failing tests in main branchnot measured by the corpus
- CH-TEST-005Integration tests cover at least the happy path of each functional flowcorpus can measure false positives only
- CH-TEST-006Edge cases and failure scenarios have test coveragecorpus can measure false positives only
- CH-TEST-007Tests cover what actually matters for the business — not just coverage metricscorpus can measure detection
- CH-SNAP-008Known technical debt is documented by the teamcorpus can measure detection
- CH-SNAP-009External service dependencies are identified and documentedcorpus can measure detection
- CH-SNAP-010Environment clearly separated (dev / staging / prod)corpus can measure detection
- CH-FSEC-001No sensitive data (tokens, keys, PII) exposed in client-side code or localStorage without encryptioncorpus can measure detection
- CH-FSEC-002Environment variables validated at build time — no secrets exposed in the browser bundlecorpus can measure detection
- CH-FSEC-003No internal API structure, route logic, or business rules leaked through the frontendcorpus can measure detection
- CH-FSEC-004XSS prevention: user input never rendered as raw HTML (dangerouslySetInnerHTML or equivalent guarded)corpus can measure detection
- CH-FSEC-005CSRF protection in place for mutation endpointscorpus can measure detection
- CH-FSTA-001Global state management is explicit and predictable (Redux, Zustand, Context — consistent usage)corpus can measure detection
- CH-FSTA-002No prop drilling beyond 2–3 levels without a state solutioncorpus can measure detection
- CH-FSTA-003Stale data handled correctly — cache invalidation strategy definedcorpus can measure detection
- CH-FSTA-004Loading, error, and empty states handled in every data-fetching componentcorpus can measure false positives only
- CH-FSTA-005No silent failures — errors always surface to the user in a meaningful waycorpus can measure false positives only
- CH-FARC-001Components have a single, clear responsibilitycorpus can measure detection
- CH-FARC-002Business logic extracted from UI components into hooks or servicescorpus can measure detection
- CH-FARC-003API calls abstracted behind a service or query layer — no fetch/axios directly in componentscorpus can measure detection
- CH-FARC-004Routing is centralized and access-controlled (protected routes implemented)corpus can measure detection
- CH-FARC-005Folder structure reflects feature boundaries, not file typescorpus can measure detection
- CH-FPRF-001Bundle size analyzed and reasonably optimized (no unintentional full-library imports)corpus can measure detection
- CH-FPRF-002Code splitting implemented for large route-based chunkscorpus can measure detection
- CH-FPRF-003Images optimized and served in modern formats (WebP, AVIF)corpus can measure detection
- CH-FPRF-004No render-blocking scripts in critical pathcorpus can measure detection
- CH-FRES-001Global error boundary implemented to prevent full app crashescorpus can measure detection
- CH-FRES-002Network failures handled gracefully (retry logic or user feedback)corpus can measure detection
- CH-FRES-003App functional under slow network conditions (skeleton states, optimistic UI where appropriate)corpus can measure detection
- CH-SEC-026La validación en el borde no se puede evadir por una normalización inconsistente del mismo input en dos caminos distintosnot measured by the corpus
- CH-SEC-027El hashing de contraseñas usa un salt generado por el propio algoritmo y un costo/rounds suficientenot measured by the corpus
- CH-SEC-028Valores sensibles (tokens de reset, códigos de verificación) emitidos por un endpoint público, nunca en el cuerpo de la respuestanot measured by the corpus
- CH-DATA-009Las operaciones check-then-act sobre un único registro (códigos de un solo uso, cupones, tokens) son atómicasnot measured by the corpus
- CH-SEC-029El callback de OAuth/OIDC valida state/nonce/PKCE atados a la sesión, y rechaza cuando falta cualquiera de los dos ladosnot measured by the corpus
- CH-SEC-030La validación de Origin/Referer usa comparación exacta o una lista cerrada, no match de prefijonot measured by the corpus
- CH-SEC-031La validación de JWT verifica issuer (iss) y audience (aud) entre distintos emisores, y verifica el tipo/propósito del token (typ/purpose) cuando el MISMO emisor firma tokens de distinto usonot measured by the corpus
- CH-SEC-032El flujo de login no revela si un usuario existe por timing o diferencia de respuestanot measured by the corpus
- CH-SEC-033Una URL provista por el usuario, consultada desde el servidor, bloquea rangos privados/internos y valida cada redirectnot measured by the corpus
- CH-SEC-034Credentials and personal data never travel in the URL: every form that sends a password, a token or personal data uses an explicit POST (or a server action), and no code reads credentials from the query string or logs themnot measured by the corpus