Code Review

by davila78da17d671b6fNo license32K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Perform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code quality. Covers security, performance, testing, and design review.

Instructions onlySoftware Development
AI-generated overview

Guides code reviews of pull requests using Sentry engineering practices, covering security, performance, testing and design.

What it does
This skill provides a structured checklist for reviewing code changes in Sentry projects. It lists problems to look for, such as runtime errors, performance issues, side effects, backwards compatibility breaks, ORM query problems and security vulnerabilities. It also covers design assessment, test coverage expectations, when to escalate to senior engineers, and how to phrase feedback. It includes example patterns for Python/Django, TypeScript/React and security issues.
When to use it
Use it when reviewing pull requests, examining code changes, or giving feedback on code quality. It suits reviewers who want a consistent, risk-focused review process aligned with Sentry engineering practices.
Requirements
No tools, packages or credentials are required; it is instructions only and ships no scripts.

Sentry Code Review

Follow these guidelines when reviewing code for Sentry projects.

Review Checklist

Identifying Problems

Look for these issues in code changes:

  • Runtime errors: Potential exceptions, null pointer issues, out-of-bounds access
  • Performance: Unbounded O(n²) operations, N+1 queries, unnecessary allocations
  • Side effects: Unintended behavioral changes affecting other components
  • Backwards compatibility: Breaking API changes without migration path
  • ORM queries: Complex Django ORM with unexpected query performance
  • Security vulnerabilities: Injection, XSS, access control gaps, secrets exposure

Design Assessment

  • Do component interactions make logical sense?
  • Does the change align with existing project architecture?
  • Are there conflicts with current requirements or goals?

Test Coverage

Every PR should have appropriate test coverage:

  • Functional tests for business logic
  • Integration tests for component interactions
  • End-to-end tests for critical user paths

Verify tests cover actual requirements and edge cases. Avoid excessive branching or looping in test code.

Long-Term Impact

Flag for senior engineer review when changes involve:

  • Database schema modifications
  • API contract changes
  • New framework or library adoption
  • Performance-critical code paths
  • Security-sensitive functionality

Feedback Guidelines

Tone

  • Be polite and empathetic
  • Provide actionable suggestions, not vague criticism
  • Phrase as questions when uncertain: "Have you considered...?"

Approval

  • Approve when only minor issues remain
  • Don't block PRs for stylistic preferences
  • Remember: the goal is risk reduction, not perfect code

Common Patterns to Flag

Python/Django

python
# Bad: N+1 queryfor user in users:    print(user.profile.name)  # Separate query per user
# Good: Prefetch relatedusers = User.objects.prefetch_related('profile')

TypeScript/React

typescript
// Bad: Missing dependency in useEffectuseEffect(() => {  fetchData(userId);}, []);  // userId not in deps
// Good: Include all dependenciesuseEffect(() => {  fetchData(userId);}, [userId]);

Security

python
# Bad: SQL injection riskcursor.execute(f"SELECT * FROM users WHERE id = {user_id}")
# Good: Parameterized querycursor.execute("SELECT * FROM users WHERE id = %s", [user_id])

References

Source and attribution

Source:davila7/claude-code-templatesincli-tool/components/skills/sentry/code-reviewat commit8da17d6

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal