This page lists the external standards, official docs, and reference material used to guide BeforeCode's CLI, documentation, release process, and repository workflow.
BeforeCode does not require these resources to use the CLI. They are included so contributors can understand the decisions behind the project and keep future changes aligned with established practices.
| Area | Reference | Why it matters |
|---|---|---|
| npm package publishing | Creating and publishing unscoped public packages | Defines how public unscoped packages such as beforecode are published. |
| npm provenance | Generating provenance statements | Guides supply-chain metadata for packages published from CI. |
| npm trusted publishing | Trusted publishing for npm packages | Recommended future release path to avoid long-lived npm tokens. |
| Semantic versioning | Semantic Versioning 2.0.0 | Versioning model for published releases and breaking changes. |
| Changelog format | Keep a Changelog | Structure for readable release history. |
| Area | Reference | Why it matters |
|---|---|---|
| Workflow syntax | GitHub Actions workflow syntax | Source of truth for CI and manual release workflow configuration. |
| Manual workflow runs | Triggering a workflow | Used for the protected manual release workflow. |
| Workflow secrets | Using secrets in GitHub Actions | Guides safe handling of npm tokens and other credentials. |
| Area | Reference | Why it matters |
|---|---|---|
| Markdown syntax | Markdown Guide basic syntax | Baseline syntax for portable Markdown templates. |
| Mermaid diagrams | Mermaid flowchart syntax | Used for editable workflow and dependency diagrams in Markdown. |
| Markdown linting | markdownlint rules | Keeps repository documentation consistent and CI-friendly. |
| Area | Reference | Why it matters |
|---|---|---|
| Application security review | OWASP ASVS | Useful reference when teams expand security requirements and QA checklists. |
| npm package security | npm audit reports | Reference for dependency and package security review. |
| GitHub security policy | Adding a security policy | Helps contributors report issues responsibly. |
Use these references when changing:
package.json, release workflow, npm publishing, or provenance behavior.- Markdown templates, examples, checklists, or README diagrams.
- CLI commands that generate docs or affect AI handoff files.
- Release notes, changelog entries, and version bumps.
- Security, QA, and launch-readiness documents.
If a reference conflicts with actual repository behavior, update the implementation first or document the reason for the exception.