Skip to content
Back to skills

Spring Boot Best Practices

ASecurity

Use typed, profile-aware configuration rather than scattering `@Value` strings: ```java @ConfigurationProperties("payments") @Validated public record PaymentProperties(@NotEmpty String baseUrl, @NotNull Duration timeout) {} ``` Register it with `@ConfigurationPropertiesScan` (or `@EnableConfigurationProperties`) and keep structured defaults in `application.yaml`. Put environment-specific overrides in `application-dev.yml` and `application-prod.yml`, selecting one with `SPRING_PROFILES_ACTIVE`...

  • 549 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
developmentjavaspringkubernetes

Security analysis

A100/100

Pro scans all 11 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill spring-boot-best-practices --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Spring Boot Best Practices?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Spring Boot Best Practices
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-spring-boot-best-practices-520dd493/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-spring-boot-best-practices-520dd493)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Use typed, profile-aware configuration rather than scattering `@Value` strings:

```java
@ConfigurationProperties("payments")
@Validated
public record PaymentProperties(@NotEmpty String baseUrl,
                                @NotNull Duration timeout) {}
```

Register it with `@ConfigurationPropertiesScan` (or `@EnableConfigurationProperties`) and keep structured defaults in `application.yaml`. Put environment-specific overrides in `application-dev.yml` and `application-prod.yml`, selecting one with `SPRING_PROFILES_ACTIVE`. Use environment variables, Kubernetes Secrets, Vault, or `spring.config.import` for credentials; never commit or bake secret values into properties.

Validation should fail fast at startup using `@Validated` and Jakarta constraints such as `@NotNull` and `@NotEmpty`. Records provide immutable, type-safe configuration and make duration, URLs, and numeric limits explicit. Avoid `@Value` for larger configuration groups, avoid silent empty defaults for required settings, and do not log secret values. Keep configuration ownership near the feature that consumes it and test each required profile and startup validation path.


Files in this skill

  • eval-1.baseline.md857 B
  • eval-1.with-skill.md1.3 KB
  • eval-2.baseline.md711 B
  • eval-2.with-skill.md1 KB
  • eval-3.baseline.md750 B
  • eval-3.with-skill.md1.1 KB
  • trigger-1.md132 B
  • trigger-2.md125 B
  • trigger-3.md145 B
  • trigger-4.md138 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…