-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.coderabbit.yaml
More file actions
46 lines (46 loc) · 1.95 KB
/
Copy path.coderabbit.yaml
File metadata and controls
46 lines (46 loc) · 1.95 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
language: en-US
reviews:
auto_review:
enabled: false
profile: assertive
request_changes_workflow: true
high_level_summary: true
poem: false
review_status: true
collapse_walkthrough: false
path_filters:
- "!devvit/dist/**"
- "!devvit/node_modules/**"
- "!**/package-lock.json"
path_instructions:
- path: "*.py"
instructions: |
Review for security issues — validate all user inputs.
Check for proper error handling and logging.
- path: "devvit/src/**/*.ts"
instructions: |
Devvit (Reddit Developer Platform) app. Enforce the migration invariants:
moderator names must always be anonymized (INV-1, never a real name);
only post/comment permalinks may be linked, never user profiles (INV-2);
removal-reason text must be email-censored and pipe-escaped (INV-4);
wiki content must stay under the 512KB cap (INV-3); the content hash used
for skip-if-unchanged must exclude volatile data like the Last Updated
timestamp (INV-6); ingest must be idempotent/deduped since there is no
daemon (INV-5). Verify Devvit API usage (reddit.getModerationLog,
get/updateWikiPage, context.redis, scheduler) and flag any unvalidated
// TODO(devvit-api) call. Prefer type-safe, injected clients over globals.
- path: "devvit/test/**/*.ts"
instructions: |
Offline mock-Reddit test harness. Check that the security invariants
(anonymize, no profile links, PII strip, dedup, retention, hash-skip)
are actually asserted, and that mocks faithfully match the real Devvit
API shapes they stand in for.
- path: ".github/workflows/**"
instructions: |
Check for command injection via untrusted GitHub context variables.
Verify secrets are not exposed in logs.
- path: "Dockerfile"
instructions: |
Check for security best practices — non-root user, minimal base image.
chat:
auto_reply: true