code-review

Sử dụng khi xem xét PR hoặc trước khi mở PR — thiết kế API, an toàn null, lỗi, tương thích ngược, phụ thuộc, bảo mật và chất lượng kiểm thử.

npx skills add https://github.com/contentstack/contentstack-management-javascript --skill code-review

Code review – Contentstack Management JavaScript SDK

When to use

  • Reviewing someone else’s PR or self-review before submission.
  • Verifying API surface, errors, compatibility, dependencies, security, and tests.

Instructions

Work through the checklist below. Optionally tag items with severity: Blocker, Major, Minor.

1. API design and stability

  • Public API: New or changed public exports documented with JSDoc, consistent with lib/contentstack.js and lib/contentstackClient.js.
  • TypeScript surface: types/** updated when signatures or exports change.
  • Backward compatibility: No breaking changes without explicit agreement (e.g. major version).
  • Naming: CMA terminology and lib/stack/ patterns.

Severity: Breaking public API without approval = Blocker. Missing JSDoc/types on new public API = Major.

2. Error handling and robustness

  • Errors: Flow through lib/core/contentstackError.js (or equivalent), preserving status and safe request metadata.
  • Null safety: No unsafe assumptions on optional API fields.
  • Secrets: No logging of full authtoken, authorization, or management_token.

Severity: Wrong or missing error handling in new code = Major.

3. Dependencies and security

  • Dependencies: New or upgraded deps justified; prefer lodash / axios patterns.
  • SCA: Snyk / Dependabot findings addressed or deferred with a ticket.

Severity: Critical/high vulnerability unfixed in scope = Blocker.

4. Testing

  • Unit: Coverage under test/unit/ with HTTP mocked; register in test/unit/index.js.
  • Sanity: When needed, update test/sanity-check/api/*-test.js and sanity.js; npm run build first; env per testSetup.js — no secrets in repo.

Severity: No tests for new behavior = Blocker. Flaky tests = Major.

5. Severity summary

  • Blocker: Must fix before merge (breaking API, security, no tests for new code).
  • Major: Should fix (error handling, missing docs, flaky tests).
  • Minor: Nice to fix (style, minor docs).

Thêm skills từ contentstack

cms-assets
contentstack
Hướng dẫn các nhà phát triển cách tổ chức, phân phối và chuyển đổi tài nguyên trong Contentstack. Bao gồm cấu trúc thư mục, các phép chuyển đổi của Image Delivery API, xuất bản…
cms-branches-aliases
contentstack
Tư vấn cho nhà phát triển về cách sử dụng Contentstack branches để phát triển nội dung độc lập và aliases để triển khai nội dung không gián đoạn. Bao gồm chiến lược branch,…
cms-data-modeling-best-practices
contentstack
Hướng dẫn các nhà phát triển mô hình hóa nội dung trong Contentstack bằng cấu trúc tái sử dụng đơn giản nhất. Kỹ năng này giải thích khi nào nên sử dụng loại nội dung, tham chiếu, toàn cục…
cms-live-preview-visual-builder-support-assistant
contentstack
Chẩn đoán và hướng dẫn triển khai Contentstack Live Preview và Visual Builder. Theo dõi ngữ cảnh xem trước, xác định hợp đồng bị hỏng, và đề xuất…
cms-releases
contentstack
Tư vấn cho nhà phát triển về cách sử dụng Contentstack Releases để triển khai nội dung đồng bộ và nguyên tử. Bao gồm tạo bản phát hành, quản lý mục, triển khai theo giai đoạn,…
cms-roles-permissions
contentstack
Tư vấn cho các nhà phát triển về việc thiết kế vai trò, quyền hạn, nhóm và quyền truy cập token trong Contentstack. Giải thích vai trò tích hợp sẵn, vai trò tùy chỉnh, việc hợp nhất quyền hạn,…
cms-taxonomy
contentstack
Tư vấn cho nhà phát triển về cách sử dụng Contentstack Taxonomy để phân loại nội dung có cấu trúc, phân cấp và lọc phía phân phối. Bao gồm sự khác biệt giữa taxonomy và tags,…
cms-tokens-authentication
contentstack
Tư vấn cho nhà phát triển cách chọn phương thức xác thực Contentstack và loại token phù hợp cho các trường hợp sử dụng frontend, backend, tự động hóa và ứng dụng bên thứ ba.…