‹ BackHN Continuity

Thread

There is more to code review than (automatable) detection

165 points · 117 comments · utiiiD

  1. metalspot · · focus · HN ↗
    The true reason why code review is universal is that it provides a liability shield for negligence. Negligence is interesting. It has nothing to do with whether or not you ship something broken. As long as you follow a process that attempts to not ship something broken, then you are not negligent.

    Engineers played along with this farce because code review served valuable team collaboration, coordination and management functions, about which the author of the article is correct.

    Understanding a system by reading code is harder than understanding a system by writing code.

    If AI can generate code at 100X, 1000X, or 10000X human capacity (no ceiling here), and you are gated on code review as your mechanism for system understanding, then a team's productive output will barely increase.

    If companies want to compete in the world of AI generated code, human code review has to go. The only question is, what replaces it?

    Continuing to apply human code review to AI generated code is negligent, if you are shipping at AI generation speed, with that as your only gate, and no other systems and processes to validate correctness and limit risk.

    On the engineering side we can adapt easily.

    Code review was never about finding bugs. When we do code review the first thing we check is: "do the tests pass?" Then we look at the change and the test coverage added for it and ask: "does the test coverage adequately demonstrate the functionality of the code?" The we ask: "What is the scope and potential impact of this change?" "What is the deployment and rollback plan and how will we monitor and detect defects after deployment?"

    Code review was never about the code. It made the lawyers happy and provided a vehicle for doing the things that actually make systems work.

    1. Anamon · · focus · HN ↗
      > If companies want to compete in the world of AI generated code, human code review has to go.

      This is a HUGE non-sequitur. It only follows if by "compete" you mean producing more LoC. How often does that translate to market fit or economic success?

      This is the mindset that makes me want to leave this industry immediately. Somehow, an industry that already annoyed me with how much "mediocre is good enough" was an acceptable stance, with the emergence of LLM coding tools suddenly decided that "absolute dogshit is good enough" was just as acceptable, as long as everybody else is also fine with eliminating the few quality standards they might have had.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.