erikpr1994 avatar

code-review

Use when reviewing code changes or conducting PR reviews.

作者 erikpr1994|オープンソース

Code Review

Goal: Find bugs, ensure quality, share knowledge.

Process

UNDERSTAND -> What changed and why?
EXAMINE    -> Check code systematically
TEST       -> Run it yourself
FEEDBACK   -> Provide actionable comments
FOLLOW-UP  -> Verify fixes

Examine Code

git diff main...feature-branch --stat
git checkout feature-branch && npm test

Check:

  • Correctness: Logic? Edge cases? Error paths?
  • Security: Input validation? Auth checked?
  • Testing: Tests exist? Cover regressions?

Feedback Severity

LevelMeaningAction
CriticalBug, securityMust fix
ImportantLogic errorShould fix
MinorStyle, namingCan fix later

Good Format:

**[Important]** Missing null check

`user` could be null if API fails. Throws at line 45.

Review Checklist

  1. Logic errors - Will it work?
  2. Security holes - Can it be exploited?
  3. Error handling - Will it crash?
  4. Test coverage - Will regressions be caught?

Block PR If

  • Hardcoded credentials
  • Disabled security checks
  • Tests that always pass
  • Catch-all error swallowing

Decision Criteria

FindingAction
Critical issueBlock merge
Important issueRequest changes
Only minor/nitpicksApprove with comments

Pairs with: pr-workflow, verification, tdd