The mesh's standing quality bar: clean, correct, finished work — documented and tested, with no rough-in left for "later". "No hacks, no temporary fixes"; "do the long work"; "best craftsmanship, always." This project already states the bar in its own words; adopting the standard makes it the shared, checkable floor rather than folklore.
Canonical, project-agnostic source:
assets/references/fairyfox.io/hub/standards/engineering-quality.md. Its companion is proof —
../plans/testing.md (the test suite) — this note is about the bar.
The rules (and where this project already lives them)
- No hacks, no temporary fixes, no bad fallbacks. Prefer the correct, clean solution even when
it's the longer route; if the only path is hacky, surface it and ask (a stated blocker beats a
silent workaround). This is
working-agreements.md§A2 (build the solution, don't offload) applied to how the solution is built. - Do the long work — phases, one finished body of work at a time. A phase that is 90% done is not
done; when work is deep, plan it across more phases, not fewer. Comprehensive-and-right outranks
soon. Pairs with
planning.md. - Best craftsmanship, always — proportionate, never absent. From the smallest DPL helper to the
provider framework, the work is genuinely well made. Ties to the owner's standing
working-agreements.md§A4 (prefer the higher-quality option, always). - Clean, modern, modular, focused code. Small units, clear boundaries, no needless duplication —
the engine/target split (
working-agreements.md§A3, "don't duplicate") and the floor-up modular decompositions (Home/SingleView/Manage/listManifest/contentSafety/DPL) are this rule in practice. - Full documentation + doc-comments. Public surfaces carry JSDoc; the notes explain how it's built.
See
documentation.md(the JSDoc house-style + doc-site) anddocs-lifecycle.mdrole inrepo-hygiene.md. - Fearless refactoring, behind the test gate — and update the tests with the refactor. This is
working-agreements.md§B1/§B5 (regression-test every change; don't regress quality metrics) plus../plans/testing.md. - Fidelity to the source of truth. Change only what the task requires. The sharpest case here is
never corrupt or lose a user's generated images or
user-settings.json(CLAUDE.md Project Preferences); the general principle is don't rewrite/normalize/reorder what you weren't asked to. - UX is not negotiable where there's a user. No clunky/janky/interrupting behaviour — the polished
result is the bar. This is
working-agreements.md§B3 (verify UI by looking) and the CLAUDE.md preference: "keep the app feeling like polished software, not a dev tool."
Verify (is it being followed?)
The per-standard slice the compliance audit aggregates — done/partial/missing:
- No hacks / temp-fixes / bad-fallbacks shipped in place of the correct solution (read recent changes; no TODO-hack markers or silent workarounds).
- Features land finished — built + reviewed + tested + documented — not rough-in for "later".
- Code is clean/modern/modular/focused; public surfaces carry doc-comments; docs are current.
- Refactors came with test updates, not test rot.
- Source-of-truth fidelity respected: no incidental rewrites of user data / settings / images.
- Ship contract (hub 0.21.0): OpenSSF Scorecard ≥ 7.0 holds (evidence:
scorecard.yml+ the security badge /working-agreements.md§B5); tech debt removed, not deferred (evidence: SonarCloud tech-debt gate + the maintenance sweep); open PRs/issues triaged as part of shipping (evidence: the pre-releasegh pr list/gh issue listcheck perCLAUDE.md"GitHub Is Part of Default Management").
The ship contract (hub 0.21.0)
"Done" carries a floor, not just "it works": the OpenSSF Scorecard stays ≥ 7.0, tech debt is
removed rather than deferred, and open PRs/issues are triaged as part of shipping — not left to
rot. RAP already tracks Scorecard/Sonar/coverage as must-hold-or-rise metrics
(working-agreements.md §B5/§F) and runs a maintenance sweep
(maintenance-sweep.md); this names the floor explicitly. Recorded in
adoption-manifest.md (ship-contract folded here).