Use when assessing or hardening a deployable TYPO3 SITE/PROJECT repo (composer type:project + Docker/Compose) — not an extension. Triggers on: compose.yaml/docker-compose.yml + config/sites or config/system in a TYPO3 repo, site conformance, gold standard, project conformance, container/Compose topology, Concourse pipeline review, supply-chain (Trivy/SBOM/cosign), secret-free settings.php/additional.php, Valkey cache, ofelia scheduler, image digest pinning, .gitlab-ci validate-only. For EXTENSI…
Files included with this skill beyond the listing page.
skill mdSKILL.md4,174 B
docsSUMMARY.md572 B
History
First seen on skills.sh
First recorded snapshot · 3 installs
SKILL.md
TYPO3 Site / Project Conformance
Score and harden a deployable TYPO3 site distribution against the Netresearch gold standard. This is the site/project counterpart to typo3-conformance (which scopes to extensions).
When to use
A repo with composer.json"type": "project"and a root Compose file.
(only pyyaml required). Scores a target repo and prints PASS/FAIL per rule.
typo3-14-gold is a runnable reference implementation that scores 100 %; typo3-project-standard is the human-readable companion. Both are Netresearch-internal and optional. Propose rule changes in gen_rules.py.
The seven rule families
Family
Intent
STRUCT
TYPO3-native layout: config/ at composer-project root, no build/config, config/sites/*/config.yaml, committed composer.lock, .gitignore excludes vendor/var/public + live-env files
CONTAINER
compose.yaml (not docker-compose.yml); images pinned — third-party by @sha256 digest or a non-floating tag (no :latest/:edge), first-party registry.netresearch.de images may track a floating tag (internal, trusted); healthchecks + deploy.resources.limits + restart on persistent services; no direct docker.sock mount
CI
composer audit → Trivy gate → SBOM → cosign; CI task images pinned; fly download checksum-verified; secret detection; test gate; updates via MR
DEPLOY
Valkey (auth + eviction + no persistence); ofelia scheduler via socket-proxy; weekly restore-verification; logs to stdout/stderr