engineering-handbook/code-review-rubric.md
Adam Moussa e057e8ab84 Add CDK layout and code review rubric to handbook index
Both pages existed in working drafts but were not linked from the
README table of contents, so they were undiscoverable. Add them to the
index alongside the related SAM layout and code review pages.
2026-06-02 19:36:09 -04:00

36 lines
976 B
Markdown

# Code Review Rubric
## Finding Categories
| Category | Meaning | Action Required |
|---|---|---|
| BLOCK | Must fix before merge | Yes -- PR cannot merge |
| FIX | Should fix, strong recommendation | Yes -- unless explicitly deferred with issue |
| NIT | Optional improvement, style preference | No -- author's discretion |
| QUESTION | Needs clarification before reviewer can assess | Yes -- answer required |
## Review Checklist
- Correctness: does the code do what the PR says?
- Security: OWASP top 10, secrets handling, input validation at boundaries
- Sea Haven conventions: naming, secrets placement, Lambda defaults, IaC patterns
- Operational readiness: logging, error handling, monitoring, CI/CD
- Tests: appropriate coverage for the change
## Output Format
```
Verdict: APPROVE | REQUEST CHANGES | NEEDS DISCUSSION
### BLOCK
- **file.py:42** -- [problem]. Why it matters: [impact]. Fix: [suggestion].
### FIX
- ...
### NIT
- ...
### QUESTION
- ...
```