1111knowledge_base :
1212 web_search :
1313 enabled : true
14+ learnings :
15+ scope : local
1416
1517reviews :
1618 profile : assertive
@@ -53,14 +55,19 @@ reviews:
5355 or upstream repositories. Report only concrete, actionable conflicts or failure modes, citing
5456 the relevant repository location or external source. Prioritize correctness, security, data loss,
5557 lifecycle, and test gaps. Do not report generic best practices, unsupported concerns, speculative
56- style comments, or unrelated refactors. Search for existing helpers before suggesting abstractions.
58+ style comments, or unrelated refactors. When changed code introduces a local implementation of a
59+ cross-cutting concern, check whether it bypasses or duplicates an established repository abstraction
60+ or nearby convention. Report only a concrete inconsistency with behavioral or maintenance impact,
61+ and allow intentional deviations.
5762
5863 - path : " **/*.{ts,tsx,js,jsx,mts,mjs,cts,cjs}"
5964 instructions : >-
6065 Check strict typing and exhaustive behavior across normal, boundary, error,
6166 cancellation, retry, and compatibility paths. Verify promises and errors are handled,
6267 existing helpers are reused, and new code introduces no `any`, unjustified double
6368 assertions, floating promises, duplicated helpers, or increased lint suppressions.
69+ When a refactor adds early-return guards that redirect a subset of inputs to a new
70+ code path, confirm the old branches for those inputs are removed or unreachable.
6471
6572 - path : " {**/*.{test,spec}.{ts,tsx,js,jsx},**/__tests__/**}"
6673 instructions : >-
@@ -76,6 +83,11 @@ reviews:
7683 Flag tests that assert in-flight behavior only after the call completes — these cannot
7784 prove the behavior fires during execution. Check that describe block names match the
7885 actual subjects of the tests they contain.
86+ For tests that assert only mock call counts, confirm a corresponding return-value
87+ assertion exists; a regression that silently returns stale fallback data can satisfy
88+ a call-count check. For code with fallback behavior, verify both the cold-start case
89+ (no prior state) and the warm case (prior state exists) are covered, as they exercise
90+ different branches.
7991
8092 - path : " apps/vscode-e2e/**"
8193 instructions : >-
@@ -115,6 +127,9 @@ reviews:
115127 Check persistence and lifecycle invariants: awaited atomic writes, rollback or explicit
116128 partial-failure behavior, cross-window state consistency, stale listeners/watchers,
117129 cancellation, idempotency, and safe restart/resume without lost or duplicated state.
130+ For async functions that read shared mutable state before an `await` and write it back
131+ after, verify the captured reference is still valid when the write executes; a concurrent
132+ mutation during the await can cause a stale snapshot to overwrite a newer state.
118133
119134 - path : " .github/**"
120135 instructions : >-
@@ -128,8 +143,20 @@ reviews:
128143 during release preparation. Verify documentation describes real behavior and contracts,
129144 and deprioritize prose-only nits that do not affect correctness or usability.
130145
146+ finishing_touches :
147+ docstrings :
148+ enabled : false
149+
131150 pre_merge_checks :
132151 override_requested_reviewers_only : true
152+ docstrings :
153+ mode : off
154+ title :
155+ mode : warning
156+ description :
157+ mode : warning
158+ issue_assessment :
159+ mode : error
133160 custom_checks :
134161 - name : Regression evidence
135162 mode : warning
@@ -140,18 +167,32 @@ reviews:
140167 snapshot. Do not demand tests for unchanged behavior, mechanical configuration, or every
141168 branch without a plausible regression scenario. Cite the changed behavior and missing
142169 evidence.
143- - name : Trust and persistence invariants
170+ - name : Security boundaries
171+ mode : error
172+ instructions : >-
173+ Fail only when a concrete changed path leaks secrets or PII, trusts or executes
174+ unvalidated input, or bypasses approval or allowlist controls. Cite the changed path
175+ and a plausible triggering scenario; pass when no such changed path exists.
176+ - name : Persistence integrity
144177 mode : error
145178 instructions : >-
146- Fail only for a concrete changed path that leaks secrets or PII, trusts or executes
147- unvalidated input, bypasses approval or allowlist controls, can lose persisted state due
148- to a missing await, non-atomic write, or omitted default propagation, or leaks lifecycle
149- resources. Cite the path and a plausible triggering scenario; pass when no such changed
150- path exists.
179+ Fail only when a concrete changed persistence path can lose or corrupt state because an
180+ operation is not awaited, a write is non-atomic, rollback or explicit partial-failure
181+ behavior is missing, or a persisted default is not propagated to a consumer. Cite the
182+ changed path and a plausible triggering scenario; pass when no such changed path exists.
183+ - name : Lifecycle resource cleanup
184+ mode : warning
185+ instructions : >-
186+ Fail only when a concrete changed lifecycle path can leak a listener, watcher, provider,
187+ timer, task, or other resource, or can duplicate work after cancellation, disposal, or
188+ restart. Cite the changed path and a plausible triggering scenario; pass when no such
189+ changed path exists.
151190
152191 tools :
153192 eslint :
154193 enabled : true
194+ github-checks :
195+ enabled : true
155196 actionlint :
156197 enabled : true
157198 shellcheck :
0 commit comments