Review bonus
The reviews required from the review bonus are in some places called manual reviews. It means reviews that are not merely done using tools such as PHP_CodeSniffer or PHPStan.
As Drupal is such a cool project, many people want to contribute to it. We need your help to manage the flood of applications, so we created the Review Bonus system. This system rewards people who are willing to help out with a bonus by prioritizing their application.
This will speed up your own project through the review process and you will learn a lot. The hope is that you will continue your involvement thereafter.
How it works
In order to join the Review Bonus system, you should complete the following steps:
- Review at least three different project applications whose status is Needs review.
- Add a link to the comment you created in the issue summary of your own application issue, for example creating a new section (Manual reviews of other projects) where the links are listed.
- Then add PAreview: review bonus in the Issue Tags field for your application.
Once the above steps are completed, you have joined the prioritized 'Review Bonus” issue queue and your application will be reviewed in turn.
What happens next
Your project will be reviewed by anyone who has time and may be set the issue to Needs Work if a project file requires changes. We will regularly check the PAreview: review bonus list and provide feedback on your module in order to get it approved.
When your own project application issue is set back to Needs Work by reviewers, the review bonus tag will be removed and your project will lose priority over the normal issues.
Once you have completed another 3 reviews, you should follow the steps above, adding in the links to the second round of reviews, and add back the tag.
Summary
To join the Review Bonus system, you are asked to complete a minimum of 3 manual reviews of other applications for a maximum of two rounds.
How to review other project applications
As mentioned above, we are always running short on project application reviewers, so we need your help in manually reviewing other project applications. Whether joining the Review Bonus program or just getting involved, you can refer to the following guidance for reviewing other project applications.
- Read How to review security advisory coverage applications and sub-pages.
- Read Writing secure code and sub-pages.
- Learn from others how they did a review, checkout closed issues that lead to a project promotion.
- You can use automated tools for review, but you must always do an additional manual review (reading through the source code) and comment on the code. If you don't do a manual review of the code by yourself, you may lose the bonus.
- Pick the oldest application from the review bonus list and get started! (If it is empty pick the oldest from the "needs review" list.)
- When you post your review comment, set the issue status to needs work, if you found some problems with the project.
Further useful resources
- Security advisory coverage application checklist
- Text-Templates for typical issues
- Instructions about the current review process
- The Code review for security advisory coverage applications group!
Thank you and welcome!
Help improve this page
You can:
- Log in, click Edit, and edit this page
- Log in, click Discuss, update the Page status value, and suggest an improvement
- Log in and create a Documentation issue with your suggestion