Skip to content

Add REVIEW.md with automated PR review guidelines - #78

Closed
andypotanin wants to merge 1 commit into
latestfrom
docs/devin-review-guidelines
Closed

Add REVIEW.md with automated PR review guidelines#78
andypotanin wants to merge 1 commit into
latestfrom
docs/devin-review-guidelines

Conversation

@andypotanin

Copy link
Copy Markdown
Member

Adds a REVIEW.md instruction file that Devin Review (and other review agents) ingest automatically when analyzing PRs in this repository. It encodes repo-specific review policy: critical paths, release/versioning gates, conventions to enforce, and security expectations.

Docs-only change: no release or deploy workflow matches a root-level REVIEW.md in this repo.

Copilot AI lite review requested due to automatic review settings August 19, 2026 20:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a repository-level REVIEW.md intended to be automatically ingested by review agents, capturing repo-specific review policy for the worker-nodejs base image (critical paths, release gates, and conventions).

Changes:

  • Added REVIEW.md documenting critical areas (Dockerfile/worker.yaml/permissions) to scrutinize during reviews.
  • Documented release gating signals (which paths trigger release workflows) and conventions to enforce in CI.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread REVIEW.md

## Critical Areas (extra scrutiny)

- Dockerfile: pinned `NODE_VERSION` / `NPM_VERSION` ARGs (keep pinned), `EXPOSE ${APP_PORT}`, `USER` directive, and the inherited entrypoint contract (`/usr/local/worker/bin/entrypoint.sh` from udx-worker). Do not override ENTRYPOINT.
Comment thread REVIEW.md
Comment on lines +10 to +14
- The Dockerfile `LABEL version` is known to drift from the actual GitVersion-published version; do not treat it as the source of truth, and flag PRs that bump only the label.

## Release Model

- Merge to `latest` cuts a Minor release IF the diff touches `Dockerfile`, `ci/**`, `src/**`, or `LICENSE`. GitVersion is the version source; there is no changelog, so the PR description must state downstream impact (do worker-engine/docker-sftp need FROM-pin bumps?).
@andypotanin

Copy link
Copy Markdown
Member Author

Closing: moving this review policy into Devin's own configuration instead of repo files.

@andypotanin
andypotanin deleted the docs/devin-review-guidelines branch August 19, 2026 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants