-
-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path.coderabbit.yaml
More file actions
74 lines (65 loc) · 3.63 KB
/
Copy path.coderabbit.yaml
File metadata and controls
74 lines (65 loc) · 3.63 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
# CodeRabbit configuration
# Docs: https://coderabbit.ai/docs/configuration
language: en-US
early_access: false
reviews:
profile: thorough
request_changes_workflow: false
high_level_summary: true
poem: false
review_status: true
collapse_walkthrough: true
auto_review:
enabled: true
drafts: false
base: development
path_instructions:
- path: '**/*.cs'
instructions: |
- Match the existing style and conventions used in the file.
- Prefer small, focused changes over broad rewrites.
- Keep APIs and abstractions as simple as possible.
- Do not suggest architectural changes unless the existing design creates a concrete correctness, security, maintainability, or performance problem.
- Avoid speculative refactoring and unnecessary API churn.
- Flag new secrets, credentials, tokens, private keys, or hardcoded connection strings.
- Check authentication, authorization, token handling, cryptographic operations,
Keycloak integration, middleware, persistence, concurrency, and lifecycle changes carefully.
- Note missing or insufficient tests for security-sensitive or behavior-changing code.
- Mention ADR updates when public behavior, architecture, contracts, or configuration semantics change.
- Do not require ADR changes for purely internal refactoring or implementation details.
- path: 'src/Plugins/**'
instructions: |
- Preserve the plugin architecture and plugin boundaries.
- Do not bypass plugin contracts or duplicate host-level plugin infrastructure.
- Check plugin metadata, registration, lifecycle hooks, configuration, health checks,
middleware, security schemes, and dependency behavior when relevant.
- Flag direct coupling between plugins that bypasses defined contracts.
- Prefer existing AuthKit extension points over introducing parallel mechanisms.
- Be careful with assembly loading, reflection, dependency discovery, and plugin ordering.
- Consider behavior when plugins are disabled, missing, invalid, or partially configured.
- path: '**/*Tests/**/*.cs'
instructions: |
- Prefer focused tests that verify observable behavior.
- Check success, failure, boundary, cancellation, and concurrency cases when relevant.
- For security-sensitive code, include negative and bypass-oriented cases.
- Avoid brittle tests that depend on implementation details.
- Reuse existing test infrastructure and fixtures where possible.
- Do not request tests for trivial changes that have no meaningful behavioral impact.
- path: '**/*.csproj'
instructions: |
- Package versions must come from central package management in Directory.Packages.props.
- Do not add package references when existing framework or project dependencies are sufficient.
- Avoid unnecessary dependencies.
- Do not suggest dependency or target-framework changes without a concrete reason.
- path: 'Docs/ADR/**'
instructions: |
- ADRs should be numbered sequentially.
- New ADRs must be linked from Docs/ADR/README.md.
- The decision context should clearly describe the problem being solved.
- Document relevant alternatives and why they were not selected.
- Keep ADRs focused on architectural decisions rather than implementation details.
- Do not request ADR changes for changes that do not affect architecture, public contracts,
configuration semantics, or significant operational behavior.
chat:
auto_reply: true
base_url: https://app.coderabbit.ai