Pull Request Review Checklist
A compact checklist for catching meaningful risk without turning every review into a style debate.
1. Scope and intent
- Requirement and acceptance criteria are explicit.
- The diff solves the stated problem.
- Unrelated refactors and generated churn are absent.
2. Correctness
- Happy path works.
- Relevant empty, error, boundary, and concurrency cases are handled.
- Authorization and data ownership are preserved.
- External calls have timeout and failure behavior.
- Timezone, currency, and localization semantics are intentional when applicable.
3. Data and migrations
- Schema changes are compatible with rollout order.
- Existing rows have a safe migration path.
- Destructive changes include recovery or rollback thinking.
- Retries cannot silently duplicate side effects.
4. Tests
- Materially changed behavior has meaningful automated coverage.
- Tests assert outcomes rather than implementation trivia.
- The important failure path is tested, not only the happy path.
- Relevant existing suites pass.
5. Delivery and operations
- Logs and errors are actionable.
- Secrets are not committed or logged.
- Deploy ordering is understood.
- A rollback path exists for risky behavior changes.
Fast decision rule: request changes for a credible correctness, security, data, or delivery risk with evidence. Ask for evidence when the risk cannot yet be verified. Otherwise approve instead of manufacturing comments.