Projects stay in their lane
A project’s globs never reach into another project’s files.

A root task with **/*.ts as its input would sweep in every package’s sources, so any change anywhere would move its key. Bugs like that take days to find.
In vx a glob stops at its project: a nested project’s files are never part of another project’s inputs. Reading another project goes through dependsOn, or by name with workspaceFiles.
// what it prints
root project inputs: ['**/*.ts']
scripts/release.ts included
packages/ui/src/a.ts not included: another projectMore in Correct by default

A task sees only the env it names
Undeclared variables never reach a task, and secrets are masked in its output.

Damaged artifacts are misses
Every artifact is checked before it is restored; damage means a rebuild, not a wrong file.

The sandbox says what to allow
A refused write is named beside the failed task, with the line that allows it.

Numbers mean what you typed
Hex, exponents and fractions are refused, never quietly reinterpreted.

Releases you can verify
Binaries carry provenance, and vx upgrade checks every download’s SHA-256.