Go Code Review
Structured code review process for Go. Reviews should be constructive, specific,
and cite the relevant principle behind each finding.
Review Process
Execute these steps in order. For each finding, classify severity:
- 🔴 BLOCKER — Must fix before merge. Correctness, data loss, security.
- 🟡 WARNING — Should fix. Maintainability, idiomatic Go, clarity.
- 🟢 SUGGESTION — Consider improving. Style, naming, documentation.
1. Correctness & Safety
Error Handling
- Every error is checked. No blank identifier
_ discarding errors silently.
- Errors are wrapped with context:
fmt.Errorf("fetch user %d: %w", id, err).
- Error values compared with
errors.Is() / errors.As(), never ==.
- No
panic outside of init() or truly unrecoverable situations.
- Errors handled exactly once — no log-and-return patterns.
Nil Safety
- Pointer receivers checked before dereference when nil is a valid state.
- Map reads guarded or use comma-ok idiom.
- Channel operations consider closed/nil channels.
- Slice operations check bounds where relevant.
Concurrency
- Shared mutable state protected by
sync.Mutex or channels.
- No goroutine leaks — every goroutine has a clear termination path.
- Context propagation: all blocking calls accept and respect
context.Context.
sync.WaitGroup or errgroup.Group used for goroutine lifecycle.
2. API Design
- Exported functions have doc comments starting with the function name.
- Accept interfaces, return concrete types.
- Use functional options (
WithTimeout(d)) over config structs for optional params.
- Context is always the first parameter:
func Foo(ctx context.Context, ...).
- Return
error as the last return value.
- Avoid
bool parameters — prefer named types or options.
3. Idiomatic Go
- Uses
:= for local variables, var for zero-value intent.
- No unnecessary
else after return/continue/break.
- Guard clauses and early returns reduce nesting.
defer used for cleanup, placed right after resource acquisition.
range used over manual index iteration where appropriate.
- Struct literals use field names.
- Interfaces defined at consumer, not producer.
4. Package Structure
- Package names are short, lowercase, singular nouns.
- No circular dependencies between packages.
internal/ used for non-public packages.
cmd/ contains main packages, one per binary.
- Clear separation of concerns — no god packages.
5. Testing
- Test functions follow
TestXxx naming convention.
- Table-driven tests used for multiple input/output combinations.
- Test helpers use
t.Helper() for clean stack traces.
- No test logic in
init() — use TestMain when needed.
- Tests use
testify/assert or testify/require consistently, or stdlib only.
- Edge cases covered: empty input, nil, zero values, max values.
t.Parallel() used where safe.
6. Documentation
- All exported types, functions, and constants have doc comments.
- Doc comments start with the name of the entity.
- Package-level doc comment in
doc.go for non-trivial packages.
- Complex algorithms or business logic have inline comments explaining why.
7. Dependencies
go.mod has no replace directives in committed code (except monorepos).
- No unused dependencies.
- Dependencies are from well-maintained, reputable sources.
- Indirect dependencies are understood and acceptable.
Review Output Format
## Code Review Summary
**Files reviewed:** <list>
**Overall assessment:** APPROVE | REQUEST CHANGES | COMMENT
### Findings
#### 🔴 BLOCKER: <title>
- **File:** `path/to/file.go:42`
- **Issue:** <what is wrong>
- **Why:** <which principle or guideline>
- **Fix:** <concrete suggestion>
#### 🟡 WARNING: <title>
...
#### 🟢 SUGGESTION: <title>
...
### What's Done Well
<genuine positive observations — always include at least one>
1---2name: go-code-review3description: Comprehensive code review checklist for Go projects. Evaluates code quality, idiomatic patterns, error handling, naming, package structure, and test coverage. Use when reviewing Go code, PRs, or before merging changes. Trigger examples: "review this code", "check this PR", "code review", "review Go file". Do NOT use for security-specific audits (use go-security-audit) or performance-specific analysis (use go-performance-review).4---5
6# Go Code Review
7
8Structured code review process for Go. Reviews should be constructive, specific,
9and cite the relevant principle behind each finding.
10
11## Review Process
12
13Execute these steps in order. For each finding, classify severity:
14- 🔴 **BLOCKER** — Must fix before merge. Correctness, data loss, security.
15- 🟡 **WARNING** — Should fix. Maintainability, idiomatic Go, clarity.
16- 🟢 **SUGGESTION** — Consider improving. Style, naming, documentation.
17
18## 1. Correctness & Safety
19
20### Error Handling
21- Every error is checked. No blank identifier `_` discarding errors silently.
22- Errors are wrapped with context: `fmt.Errorf("fetch user %d: %w", id, err)`.
23- Error values compared with `errors.Is()` / `errors.As()`, never `==`.
24- No `panic` outside of `init()` or truly unrecoverable situations.
25- Errors handled exactly once — no log-and-return patterns.
26
27### Nil Safety
28- Pointer receivers checked before dereference when nil is a valid state.
29- Map reads guarded or use comma-ok idiom.
30- Channel operations consider closed/nil channels.
31- Slice operations check bounds where relevant.
32
33### Concurrency
34- Shared mutable state protected by `sync.Mutex` or channels.
35- No goroutine leaks — every goroutine has a clear termination path.
36- Context propagation: all blocking calls accept and respect `context.Context`.
37- `sync.WaitGroup` or `errgroup.Group` used for goroutine lifecycle.
38
39## 2. API Design
40
41- Exported functions have doc comments starting with the function name.
42- Accept interfaces, return concrete types.
43- Use functional options (`WithTimeout(d)`) over config structs for optional params.
44- Context is always the first parameter: `func Foo(ctx context.Context, ...)`.
45- Return `error` as the last return value.
46- Avoid `bool` parameters — prefer named types or options.
47
48## 3. Idiomatic Go
49
50- Uses `:=` for local variables, `var` for zero-value intent.
51- No unnecessary `else` after return/continue/break.
52- Guard clauses and early returns reduce nesting.
53- `defer` used for cleanup, placed right after resource acquisition.
54- `range` used over manual index iteration where appropriate.
55- Struct literals use field names.
56- Interfaces defined at consumer, not producer.
57
58## 4. Package Structure
59
60- Package names are short, lowercase, singular nouns.
61- No circular dependencies between packages.
62- `internal/` used for non-public packages.
63- `cmd/` contains main packages, one per binary.
64- Clear separation of concerns — no god packages.
65
66## 5. Testing
67
68- Test functions follow `TestXxx` naming convention.
69- Table-driven tests used for multiple input/output combinations.
70- Test helpers use `t.Helper()` for clean stack traces.
71- No test logic in `init()` — use `TestMain` when needed.
72- Tests use `testify/assert` or `testify/require` consistently, or stdlib only.
73- Edge cases covered: empty input, nil, zero values, max values.
74- `t.Parallel()` used where safe.
75
76## 6. Documentation
77
78- All exported types, functions, and constants have doc comments.
79- Doc comments start with the name of the entity.
80- Package-level doc comment in `doc.go` for non-trivial packages.
81- Complex algorithms or business logic have inline comments explaining *why*.
82
83## 7. Dependencies
84
85- `go.mod` has no replace directives in committed code (except monorepos).
86- No unused dependencies.
87- Dependencies are from well-maintained, reputable sources.
88- Indirect dependencies are understood and acceptable.
89
90## Review Output Format
91
92```
93## Code Review Summary
94
95**Files reviewed:** <list>
96**Overall assessment:** APPROVE | REQUEST CHANGES | COMMENT
97
98### Findings
99
100#### 🔴 BLOCKER: <title>
101- **File:** `path/to/file.go:42`
102- **Issue:** <what is wrong>
103- **Why:** <which principle or guideline>
104- **Fix:** <concrete suggestion>
105
106#### 🟡 WARNING: <title>
107...
108
109#### 🟢 SUGGESTION: <title>
110...
111
112### What's Done Well
113<genuine positive observations — always include at least one>
114```