Skip to content

Code Review Guidelines

Review correctness, scope, additive safety, consent boundaries, secret handling, compatibility, tests, documentation, and operational recovery. Reject unrelated changes, silent overwrites, shell interpolation, committed credentials, unsupported installers, or architecture changes without ADR approval. At least one maintainer approval is required; security-sensitive changes require security-owner review.