code-review

作者: contentstack

Use when reviewing PRs or before opening a PR — API design, null-safety, errors, backward compatibility, dependencies, security, and test quality.

npx skills add https://github.com/contentstack/contentstack-management-javascript --skill code-review

Code review – Contentstack Management JavaScript SDK

When to use

  • Reviewing someone else’s PR or self-review before submission.
  • Verifying API surface, errors, compatibility, dependencies, security, and tests.

Instructions

Work through the checklist below. Optionally tag items with severity: Blocker, Major, Minor.

1. API design and stability

  • Public API: New or changed public exports documented with JSDoc, consistent with lib/contentstack.js and lib/contentstackClient.js.
  • TypeScript surface: types/** updated when signatures or exports change.
  • Backward compatibility: No breaking changes without explicit agreement (e.g. major version).
  • Naming: CMA terminology and lib/stack/ patterns.

Severity: Breaking public API without approval = Blocker. Missing JSDoc/types on new public API = Major.

2. Error handling and robustness

  • Errors: Flow through lib/core/contentstackError.js (or equivalent), preserving status and safe request metadata.
  • Null safety: No unsafe assumptions on optional API fields.
  • Secrets: No logging of full authtoken, authorization, or management_token.

Severity: Wrong or missing error handling in new code = Major.

3. Dependencies and security

  • Dependencies: New or upgraded deps justified; prefer lodash / axios patterns.
  • SCA: Snyk / Dependabot findings addressed or deferred with a ticket.

Severity: Critical/high vulnerability unfixed in scope = Blocker.

4. Testing

  • Unit: Coverage under test/unit/ with HTTP mocked; register in test/unit/index.js.
  • Sanity: When needed, update test/sanity-check/api/*-test.js and sanity.js; npm run build first; env per testSetup.js — no secrets in repo.

Severity: No tests for new behavior = Blocker. Flaky tests = Major.

5. Severity summary

  • Blocker: Must fix before merge (breaking API, security, no tests for new code).
  • Major: Should fix (error handling, missing docs, flaky tests).
  • Minor: Nice to fix (style, minor docs).

来自 contentstack 的更多技能

brand-kit-assistant
contentstack
就Contentstack Brand Kit的概念、设置、治理及品牌化AI生成向用户提供建议。将API相关任务路由到正确的Brand Kit功能或…
official
cms-assets
contentstack
为开发人员提供关于在Contentstack中组织、交付和转换资产的建议。涵盖文件夹结构、Image Delivery API转换、发布……
official
cms-branches-aliases
contentstack
指导开发者使用Contentstack分支进行隔离的内容开发,并使用别名实现零停机的内容部署。涵盖分支策略、…
official
cms-data-modeling-best-practices
contentstack
指导开发者在Contentstack中使用最简单可复用的结构来建模内容。该技能解释了何时使用内容类型、引用、全局…
official
cms-entries
contentstack
为开发者提供关于查询、本地化、版本管理、发布和构建Contentstack条目的建议,以实现高效交付。重点关注CDA的使用、引用……
official
cms-environments-publishing
contentstack
为开发人员提供关于配置环境、发布内容、使用交付和预览令牌、利用Sync API以及了解CDN和…的建议
official
cms-live-preview-visual-builder-support-assistant
contentstack
诊断并指导Contentstack Live Preview和Visual Builder的实施。追踪预览上下文,识别损坏的契约,并推荐…
official
cms-localization
contentstack
Advise developers on Contentstack localization: language setup, fallback chains, localized vs unlocalized entries, non-localizable fields, and multi-locale…
official