-
Notifications
You must be signed in to change notification settings - Fork 0
Add GitHub Copilot code review instructions #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,59 @@ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| # Here Copilot Code Review Instructions are found | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ## 1. Context for copilot | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - This document provides clear instructions for conducting Copilot-powered code reviews. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - Know that code you review for in this organization is developed by RiseUp - to build cashflows by analyzing transactions, predicting patterns, and managing financial data | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - Know that RiseUp processes and stores personal financial data of customers that's pulled from open banking data sources via APIs, such as banks and credit card companies. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - RiseUp offers mobile and web apps directly to consumers, we have tens of thousands of paying users serviced by front-end in the web (html, javascript) elsa, greta and anna repositories and flutter mobile apps that deploy to android and IOS devices from the mobile_web repository | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| - RiseUp offers mobile and web apps directly to consumers, we have tens of thousands of paying users serviced by front-end in the web (html, javascript) elsa, greta and anna repositories and flutter mobile apps that deploy to android and IOS devices from the mobile_web repository | |
| - RiseUp offers mobile and web apps directly to consumers, we have tens of thousands of paying users serviced by front-end in the web (html, javascript) elsa, greta and anna repositories and flutter mobile apps that deploy to android and iOS devices from the mobile_web repository |
Copilot
AI
Feb 11, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The Markdown bold formatting is not closed (**), which will cause the rest of the document to render incorrectly. Close the bold marker (or remove bolding) so formatting doesn鈥檛 bleed into subsequent sections.
| - **Trust internal @riseupil dependencies (e.g. @riseupil/reactive-cashflow) somewhat, and focus on external dependencies when raising feedback | |
| - **Trust internal @riseupil dependencies (e.g. @riseupil/reactive-cashflow) somewhat, and focus on external dependencies when raising feedback** |
Copilot
AI
Feb 11, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This document includes detailed internal service/repository names and authentication/architecture specifics. Since files under .github/ are accessible to anyone with read access to the repo, consider reducing sensitive implementation details (or moving them to a private/internal doc) and keeping this file focused on review principles and high-level context.
| - RiseUp offers mobile and web apps directly to consumers, we have tens of thousands of paying users serviced by front-end in the web (html, javascript) elsa, greta and anna repositories and flutter mobile apps that deploy to android and IOS devices from the mobile_web repository | |
| - Know that RiseUp cares a lot about customer privacy and data protection. | |
| - apart from elsa, greta, anna and mobile_web repositories, also olaf, carmella and captain-hooks are internet facing and will process and accept dangerous input from users when calling other internal services. | |
| - our database is a mongodb nosql database | |
| - the service and repository 'hans' is responsible for customer authentication, token creation and validation | |
| - 'olaf' is the primary product proxy and API - it will intercept internet web requests, processes them, validate the session (if exists) and route them to the appropriate internal service | |
| - our customers are authenticated using 2fa, with either auth0 or descope plus an in-house OTP mechanism | |
| - we also communicate with customers using email, intercom, sms messages, push notifications | |
| - user authentication is handled by 'hans' and authorization is handled by olaf, per called endpoint using an authorizationMiddleware | |
| - very few endpoints should remain unauthenticated and when such are added or extended this should be reviewed by humans with your feedback | |
| - 3rd party and api authentication is handled in other repository (e.g. carmella with verifySignature vs a pre-shared api key or aggregator using pki) | |
| - **Tech Stack**: AWS, Vue, Node.js, TypeScript, Express, MongoDB, Jest | |
| - **Architecture**: Microservice with CQRS pattern, event-driven flows | |
| - **Trust internal @riseupil dependencies (e.g. @riseupil/reactive-cashflow) somewhat, and focus on external dependencies when raising feedback | |
| - RiseUp offers mobile and web apps directly to consumers, we have tens of thousands of paying users serviced by web front-end applications and Flutter-based mobile apps that deploy to Android and iOS devices. | |
| - Know that RiseUp cares a lot about customer privacy and data protection. | |
| - Some services are internet facing and will process and accept potentially dangerous input from users when calling other internal services. | |
| - A dedicated authentication service is responsible for customer authentication, token creation, and validation. | |
| - An API gateway acts as the primary product proxy and API entry point: it intercepts internet web requests, validates sessions (if they exist), and routes them to the appropriate internal service. | |
| - Our customers are authenticated using multi-factor authentication (MFA), combining external identity providers with an in-house one-time-password (OTP) mechanism. | |
| - We also communicate with customers using email, in-app messaging, SMS messages, and push notifications. | |
| - User authentication is handled by a dedicated authentication service and authorization is enforced at the API gateway level per endpoint using authorization middleware. | |
| - Very few endpoints should remain unauthenticated, and when such endpoints are added or extended this should be reviewed by humans with your feedback. | |
| - Third-party and API authentication is handled by separate integration services (for example, using signature verification, pre-shared API keys, or public-key infrastructure (PKI), as appropriate). | |
| - **Tech Stack**: AWS, Vue, Node.js, TypeScript, Express, MongoDB, Jest | |
| - **Architecture**: Microservice with CQRS pattern, event-driven flows | |
| - **Trust internal organization-owned dependencies (for example, internal packages published to the private registry) somewhat, and focus primarily on external dependencies when raising feedback |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is a run-on sentence with multiple clauses and mixed concerns (platforms, repos, technologies). Please split into shorter bullet points/sentences and standardize capitalization (e.g., HTML/JavaScript/Android/iOS) to improve readability and reduce ambiguity.