Code Review

davila7/claude-code-templates/cli-tool/components/skills/sentry/code-review

作者 davila78da17d671b6f无许可证32K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Perform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code quality. Covers security, performance, testing, and design review.

AI 生成的概览

依据 Sentry 工程实践指导代码审查,涵盖安全、性能、测试与设计。

功能
该技能为审查 Sentry 项目的代码变更提供结构化清单。它列出需要排查的问题,例如运行时错误、性能问题、副作用、向后兼容性破坏、ORM 查询问题以及安全漏洞。它还涵盖设计评估、测试覆盖要求、何时应升级给资深工程师复核,以及如何措辞反馈意见。其中包含 Python/Django、TypeScript/React 和安全问题的示例模式。
适用场景
适用于审查拉取请求、检查代码变更或对代码质量提供反馈的场景。适合希望采用与 Sentry 工程实践一致、以风险为重点的审查流程的审查者。
运行要求
无需任何工具、软件包或凭据;仅为说明性指令,不附带脚本。

Sentry Code Review

Follow these guidelines when reviewing code for Sentry projects.

Review Checklist

Identifying Problems

Look for these issues in code changes:

  • Runtime errors: Potential exceptions, null pointer issues, out-of-bounds access
  • Performance: Unbounded O(n²) operations, N+1 queries, unnecessary allocations
  • Side effects: Unintended behavioral changes affecting other components
  • Backwards compatibility: Breaking API changes without migration path
  • ORM queries: Complex Django ORM with unexpected query performance
  • Security vulnerabilities: Injection, XSS, access control gaps, secrets exposure

Design Assessment

  • Do component interactions make logical sense?
  • Does the change align with existing project architecture?
  • Are there conflicts with current requirements or goals?

Test Coverage

Every PR should have appropriate test coverage:

  • Functional tests for business logic
  • Integration tests for component interactions
  • End-to-end tests for critical user paths

Verify tests cover actual requirements and edge cases. Avoid excessive branching or looping in test code.

Long-Term Impact

Flag for senior engineer review when changes involve:

  • Database schema modifications
  • API contract changes
  • New framework or library adoption
  • Performance-critical code paths
  • Security-sensitive functionality

Feedback Guidelines

Tone

  • Be polite and empathetic
  • Provide actionable suggestions, not vague criticism
  • Phrase as questions when uncertain: "Have you considered...?"

Approval

  • Approve when only minor issues remain
  • Don't block PRs for stylistic preferences
  • Remember: the goal is risk reduction, not perfect code

Common Patterns to Flag

Python/Django

python
# Bad: N+1 queryfor user in users:    print(user.profile.name)  # Separate query per user
# Good: Prefetch relatedusers = User.objects.prefetch_related('profile')

TypeScript/React

typescript
// Bad: Missing dependency in useEffectuseEffect(() => {  fetchData(userId);}, []);  // userId not in deps
// Good: Include all dependenciesuseEffect(() => {  fetchData(userId);}, [userId]);

Security

python
# Bad: SQL injection riskcursor.execute(f"SELECT * FROM users WHERE id = {user_id}")
# Good: Parameterized querycursor.execute("SELECT * FROM users WHERE id = %s", [user_id])

References

来源与署名

来源:davila7/claude-code-templates位于cli-tool/components/skills/sentry/code-review提交8da17d6

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架