code-review

作者: contentstack

用於審查 PR 或開啟 PR 之前——API 設計、空值安全、錯誤處理、向後相容性、依賴、安全性與測試品質。

npx skills add https://github.com/contentstack/contentstack-management-javascript --skill code-review

Code review – Contentstack Management JavaScript SDK

When to use

  • Reviewing someone else’s PR or self-review before submission.
  • Verifying API surface, errors, compatibility, dependencies, security, and tests.

Instructions

Work through the checklist below. Optionally tag items with severity: Blocker, Major, Minor.

1. API design and stability

  • Public API: New or changed public exports documented with JSDoc, consistent with lib/contentstack.js and lib/contentstackClient.js.
  • TypeScript surface: types/** updated when signatures or exports change.
  • Backward compatibility: No breaking changes without explicit agreement (e.g. major version).
  • Naming: CMA terminology and lib/stack/ patterns.

Severity: Breaking public API without approval = Blocker. Missing JSDoc/types on new public API = Major.

2. Error handling and robustness

  • Errors: Flow through lib/core/contentstackError.js (or equivalent), preserving status and safe request metadata.
  • Null safety: No unsafe assumptions on optional API fields.
  • Secrets: No logging of full authtoken, authorization, or management_token.

Severity: Wrong or missing error handling in new code = Major.

3. Dependencies and security

  • Dependencies: New or upgraded deps justified; prefer lodash / axios patterns.
  • SCA: Snyk / Dependabot findings addressed or deferred with a ticket.

Severity: Critical/high vulnerability unfixed in scope = Blocker.

4. Testing

  • Unit: Coverage under test/unit/ with HTTP mocked; register in test/unit/index.js.
  • Sanity: When needed, update test/sanity-check/api/*-test.js and sanity.js; npm run build first; env per testSetup.js — no secrets in repo.

Severity: No tests for new behavior = Blocker. Flaky tests = Major.

5. Severity summary

  • Blocker: Must fix before merge (breaking API, security, no tests for new code).
  • Major: Should fix (error handling, missing docs, flaky tests).
  • Minor: Nice to fix (style, minor docs).

來自 contentstack 的更多技能

cms-assets
contentstack
為開發人員提供有關在Contentstack中組織、交付和轉換資產的建議。涵蓋資料夾結構、Image Delivery API轉換、發佈……
cms-branches-aliases
contentstack
為開發人員提供使用 Contentstack 分支進行隔離內容開發以及使用別名實現零停機內容部署的建議。涵蓋分支策略,…
cms-data-modeling-best-practices
contentstack
引導開發人員在Contentstack中使用最簡單的可重用結構來建模內容。此技能說明何時使用內容類型、引用、全域…
cms-live-preview-visual-builder-support-assistant
contentstack
診斷並指導 Contentstack Live Preview 和 Visual Builder 的實作。追蹤預覽上下文,識別中斷的合約,並建議…
cms-releases
contentstack
指導開發人員使用 Contentstack Releases 進行協調、原子化的內容部署。涵蓋版本建立、項目管理、分階段部署等內容。
cms-roles-permissions
contentstack
為開發人員提供關於在Contentstack中設計角色、權限、團隊和Token存取權限的建議。解釋內建角色、自訂角色、權限合併等。
cms-taxonomy
contentstack
為開發人員提供關於使用 Contentstack Taxonomy 進行結構化、階層式內容分類及傳遞端篩選的建議。涵蓋 taxonomy 與 tags 的比較,…
cms-tokens-authentication
contentstack
為開發人員提供建議,協助他們為前端、後端、自動化及第三方應用程式使用情境選擇正確的Contentstack驗證方法與權杖類型。…