| name | code-review |
|---|---|
| description | PR checklist, branch policy, versioning notes, and security scan context for this repository. |
- Opening or reviewing a pull request.
- Checking release readiness (version, changelog, package metadata).
- Ensuring changes align with automated security and branch rules.
- PRs into
mastermust be fromstagingper .github/workflows/check-branch.yml. Verify head/base before approving merges tomaster. - If the PR does not target
master, the same rule may not apply; still follow team conventions for default branch.
- Build and tests:
dotnet buildanddotnet testoncontentstack.model.generator/contentstack.model.generator.slnsucceed (CI does not rundotnet test; see dev-workflow/SKILL.md). - Release versioning: For releases, keep
[VersionOption]in ModelGenerator.cs (CLI--version),PackageVersion/ReleaseVersionin contentstack.model.generator.csproj, and CHANGELOG.md aligned. - Auth paths: Traditional
authtokenvs--oauthremain mutually consistent; no accidental logging of secrets. - Codegen output: Changes to
ModelGeneratoror templates do not break emitted class shapes without CHANGELOG.md and version bump in contentstack.model.generator.csproj when releasing. - Dependencies: New package references are justified; Snyk/SCA will scan on PRs (sca-scan.yml).
- Security-sensitive code: HTTP, OAuth, and error handling reviewed for information disclosure and robust failure modes.
- Snyk (SCA): .github/workflows/sca-scan.yml — dependency vulnerabilities.
- CodeQL: .github/workflows/codeql-analysis.yml — static analysis for C#.
Treat new findings from these workflows as blockers until triaged or waived with documented rationale.
- License and copyright in packaged output follow
contentstack.model.generator.csprojand LICENSE / packagedLICENSE.txtas applicable. - Security: Report vulnerabilities per SECURITY.md (not via public GitHub issues).