code-review

Liste de contrôle pour les pull-requests : sécurité, identifiants Contentstack, assainissement et configuration des images.

npx skills add https://github.com/contentstack/kickstart-next-ssg --skill code-review

Code review – kickstart-next-ssg

When to use

  • Before approving or merging a pull request
  • Auditing changes that touch env vars, CMS integration, or user-facing HTML

Instructions

Secrets and configuration

  • No real .env values or delivery/preview tokens committed; use placeholders in docs only.
  • New NEXT_PUBLIC_* keys are exposed to the browser—avoid putting sensitive server-only secrets behind that prefix.

Contentstack

  • Token scopes and preview settings stay aligned with README.md (preview-capable delivery token, Live Preview environment).

Security and dependencies

HTML and XSS

  • Rich text and block copy use dangerouslySetInnerHTML only after isomorphic-dompurify in pages/index.tsx; preserve or improve sanitization when changing markup.

Images

  • New remote image domains must be reflected in next.config.mjs images.remotePatterns (or env-driven hostname) so next/image does not break at runtime.

Quality

  • Run npm run lint locally for substantive TS/React changes.

Plus de skills de contentstack

brand-kit-assistant
contentstack
Advise users on Contentstack Brand Kit concepts, setup, governance, and on-brand AI generation. Route API-specific tasks to the right Brand Kit capability or…
official
cms-assets
contentstack
Conseiller les développeurs sur l'organisation, la livraison et la transformation des assets dans Contentstack. Couvrir la structure des dossiers, les transformations de l'API de livraison d'images, la publication…
official
cms-branches-aliases
contentstack
Advise developers on using Contentstack branches for isolated content development and aliases for zero-downtime content deployments. Cover branch strategy,…
official
cms-data-modeling-best-practices
contentstack
Guidez les développeurs pour modéliser le contenu dans Contentstack en utilisant la structure réutilisable la plus simple. La compétence explique quand utiliser les types de contenu, les références, les éléments globaux…
official
cms-entries
contentstack
Advise developers on querying, localizing, versioning, publishing, and structuring Contentstack entries for efficient delivery. Focus on CDA usage, reference…
official
cms-environments-publishing
contentstack
Conseiller les développeurs sur la configuration des environnements, la publication de contenu, l'utilisation des jetons de livraison et d'aperçu, l'exploitation de l'API Sync, et la compréhension du CDN et…
official
cms-live-preview-visual-builder-support-assistant
contentstack
Diagnose and guide Contentstack Live Preview and Visual Builder implementations. Trace preview context, identify the broken contract, and recommend the…
official
cms-localization
contentstack
Advise developers on Contentstack localization: language setup, fallback chains, localized vs unlocalized entries, non-localizable fields, and multi-locale…
official