FeatureBuilder

Documentation
Source

Renderer responsibilities, the desktop boundary, and the checks run before release.

Application architecture and quality gate

Four main layers

PathResponsibility
src/ React/TypeScript interface, domain model, validation, and renderer tests.
electron/preload.cjs Narrow, typed bridge exposed to the sandboxed renderer.
electron/main.cjs Window lifecycle, file dialogs, and desktop coordination.
electron/project-store.cjs Project validation and atomic directory reads/writes.

Desktop security posture

  • The renderer has no direct Node.js access.
  • Electron context isolation and sandboxing are enabled.
  • A restrictive content-security policy limits executable content.
  • Unexpected navigation and pop-up windows are denied.
  • Identifiers are validated before becoming filenames.

Quality and packaging checks

npm run check
npm audit --audit-level=high

The checked-in workflow covers formatting/linting, types, tests, build behavior, and dependency auditing before packaging.