initial
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
# Code Review Guidelines
|
||||
|
||||
## General Principles
|
||||
- Write clean, readable, and maintainable code.
|
||||
- Follow the project's coding standards and style guides.
|
||||
- Ensure code is well-tested and documented.
|
||||
- Avoid code duplication; refactor when necessary.
|
||||
- Use meaningful names for variables, functions, and classes.
|
||||
- Keep functions and classes focused on a single responsibility.
|
||||
|
||||
## Specific Checks
|
||||
- [ ] Code follows the project's style guide (e.g., PEP8 for Python).
|
||||
- [ ] No commented-out code or debug prints in production code.
|
||||
- [ ] Proper error handling and logging.
|
||||
- [ ] Resource management (e.g., closing files, releasing network connections).
|
||||
- [ ] Security best practices (input validation, output encoding, etc.).
|
||||
- [ ] Performance considerations (avoid unnecessary loops, optimize database queries).
|
||||
- [ ] Unit tests are present and passing for new code.
|
||||
- [ ] Changes are backward compatible or have a migration plan.
|
||||
@@ -0,0 +1,22 @@
|
||||
# Security Review Guidelines
|
||||
|
||||
## General Principles
|
||||
- Follow the principle of least privilege.
|
||||
- Validate and sanitize all user inputs.
|
||||
- Use secure coding practices to prevent common vulnerabilities.
|
||||
- Keep dependencies up to date and monitor for known security issues.
|
||||
- Implement proper authentication and authorization mechanisms.
|
||||
- Encrypt sensitive data at rest and in transit.
|
||||
- Log security-relevant events and monitor for suspicious activities.
|
||||
|
||||
## Specific Checks
|
||||
- [ ] Input validation and sanitization (SQL injection, XSS, command injection, etc.).
|
||||
- [ ] Proper authentication and session management.
|
||||
- [ ] Authorization checks (users can only access resources they are permitted to).
|
||||
- [ ] Secure handling of sensitive data (passwords, tokens, PII).
|
||||
- [ ] Use of up-to-date and secure dependencies (no known vulnerabilities).
|
||||
- [ ] Proper error handling that does not leak sensitive information.
|
||||
- [ ] Secure configuration (e.g., not using default passwords, disabling unnecessary services).
|
||||
- [ ] Communication security (use of HTTPS, proper certificate validation).
|
||||
- [ ] Protection against CSRF, clickjacking, and other web vulnerabilities.
|
||||
- [ ] Secure file uploads (if applicable).
|
||||
Reference in New Issue
Block a user