Web app for Walkable LLC, built using a template built with Next.js 15, React 19, Tailwind CSS v4, and Motion-Primitives Pro.
The repo includes the following:
- Multi-stage Dockerfile to build multi-arch images, pushing artifacts to public Docker registry
- Automated build and deployment with Cloudflare’s integrated CI/CD system: Workers Builds for successful merges to main
- Test/deploy preview to Netlify before publishing to production
- Separate build and runtime node.js hardened images
- Uses cache mounts to speed up build: only rebuilds layers when
package*.jsondependencies are changed (dependent on builder machine, most effective when persistent storage/NVMe is available) - Instructions ordered so that cached layers are reused if the same hash is present
- Runtime stage removes build tools, libraries, dependencies to reduce potential attack surface and final image size
- Container runs as rootless. Necessary directories e.g.
/app/.next/standalonechanged ownership to usernodeto run container under least privilege
- PR branch must be up to date with main before merging
- All review threads must be resolved before merging
- Linear code history is required
- Commits must have verified SSH signatures
- Dependency review action to scan PRs for dependency changes and vulnerabilities
- CodeQL security scanning to scan code on push, PRs to main, and schedule. Alerts at high severity/above blocks merge
- No force-pushing to main. Commits must be made to a working branch and submitted via PR
- Collaborators (agent) cannot merge
- Actions to be pinned to commit SHAs
- Only select actions are allowed
- Block commits that contain secrets
