Code Review

getsentry/skills/skills/code-review

作者 getsentryd18b7aa8ba878354e5c348310230e652f7690f9c無授權條款1K 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫6 天前更新

Perform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code quality. Covers security, performance, testing, and design review.

AI 產生的概覽

依循 Sentry 工程實務指導程式碼審查,涵蓋安全性、效能、測試與設計。

功能
此技能為審查 Sentry 專案的程式碼變更提供結構化檢查清單。它列出應排查的問題,例如執行階段錯誤、效能問題、副作用、向後相容性破壞、ORM 查詢問題以及安全漏洞。它也涵蓋設計評估、測試涵蓋率要求、何時應升級由資深工程師複核,以及如何措辭回饋意見。內容包含 Python/Django、TypeScript/React 與安全性問題的範例模式。
適用情境
適用於審查提取要求(pull request)、檢視程式碼變更或對程式碼品質提供回饋的情境。適合希望採用與 Sentry 工程實務一致、以風險為重點之審查流程的審查者。
執行需求
不需要任何工具、套件或憑證;僅為說明性指示,不附帶指令碼。

Sentry Code Review

Follow these guidelines when reviewing code for Sentry projects.

Review Checklist

Identifying Problems

Look for these issues in code changes:

  • Runtime errors: Potential exceptions, null pointer issues, out-of-bounds access
  • Performance: Unbounded O(n²) operations, N+1 queries, unnecessary allocations
  • Side effects: Unintended behavioral changes affecting other components
  • Backwards compatibility: Breaking API changes without migration path
  • ORM queries: Complex Django ORM with unexpected query performance
  • Security vulnerabilities: Injection, XSS, access control gaps, secrets exposure

Design Assessment

  • Do component interactions make logical sense?
  • Does the change align with existing project architecture?
  • Are there conflicts with current requirements or goals?

Test Coverage

Every PR should have appropriate test coverage:

  • Functional tests for business logic
  • Integration tests for component interactions
  • End-to-end tests for critical user paths

Verify tests cover actual requirements and edge cases. Avoid excessive branching or looping in test code.

Long-Term Impact

Flag for senior engineer review when changes involve:

  • Database schema modifications
  • API contract changes
  • New framework or library adoption
  • Performance-critical code paths
  • Security-sensitive functionality

Feedback Guidelines

Tone

  • Be polite and empathetic
  • Provide actionable suggestions, not vague criticism
  • Phrase as questions when uncertain: "Have you considered...?"

Approval

  • Approve when only minor issues remain
  • Don't block PRs for stylistic preferences
  • Remember: the goal is risk reduction, not perfect code

Common Patterns to Flag

Python/Django

python
# Bad: N+1 queryfor user in users:    print(user.profile.name)  # Separate query per user
# Good: Prefetch relatedusers = User.objects.prefetch_related('profile')

TypeScript/React

typescript
// Bad: Missing dependency in useEffectuseEffect(() => {  fetchData(userId);}, []);  // userId not in deps
// Good: Include all dependenciesuseEffect(() => {  fetchData(userId);}, [userId]);

Security

python
# Bad: SQL injection riskcursor.execute(f"SELECT * FROM users WHERE id = {user_id}")
# Good: Parameterized querycursor.execute("SELECT * FROM users WHERE id = %s", [user_id])

References

來源與署名

來源:getsentry/skills位於skills/code-review提交d18b7aa

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架