The 152-point checklist
Thirteen areas — Server Actions, middleware/proxy, RSC exposure, env leaks, auth, database RLS, rate limiting, security headers, supply chain, file uploads, SSRF, error handling, logging. Every item tells you what to check and what good looks like.