code-review-patterns

Solid

Code review checklist, what to look for, how to give feedback, PR review flow. Use when reviewing a pull request, or when preparing code for review.

Code & Development 30 stars 9 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 82/100

Stars 20%
50
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Code Review Patterns ## The Goal of Code Review Code review is NOT about finding mistakes to win arguments. It is about: 1. **Correctness** — Does the code do what it's supposed to do? 2. **Safety** — Are there security or data integrity risks? 3. **Clarity** — Will the next developer understand this in 6 months? 4. **Consistency** — Does this follow the established patterns in the codebase? ## What to Look For — Priority Order ### P0 — Block (must fix before merge) ``` □ Security vulnerability (SQL injection, XSS, auth bypass, hardcoded secrets) □ Data loss risk (wrong delete scope, missing transaction, no backup) □ Correctness bug (wrong logic, off-by-one, race condition) □ Broken tests or test coverage dropped below 80% □ Deployment risk (migration without rollback, breaking API change) ``` ### P1 — Should Fix ``` □ Missing error handling (silent catch, swallowed exception) □ N+1 query problem □ Function over 50 lines (extract responsibility) □ File over 800 lines (extract module) □ Nesting depth > 4 (use early returns) □ Missing input validation on public endpoints □ console.log / debug statements left in □ TODO comments without tracking issue ``` ### P2 — Consider Fixing ``` □ Naming: unclear variable/function names □ Missing comments on non-obvious logic □ Magic numbers (use named constants) □ Duplicate code (extract utility) □ Missing type annotations ``` ### P3 — Optional / Style ``` □ Formatting inconsistency (should be caught by linter/prettier) □ Minor nam...

Details

Author
sabahattink
Repository
sabahattink/antigravity-fullstack-hq
Created
8 months ago
Last Updated
5 days ago
Language
PowerShell
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category