Code review and static analysis
How human and AI code review work, what reading a diff can and cannot catch, static analysis, and how to review code written by agents.
Start here
What is code review?
Code review is the practice of reading a proposed code change before it merges, to catch defects, share knowledge, and keep the codebase consistent.
Concepts
What is AI code review?
AI code review is the use of a language model to read a pull request and comment on bugs, style, and risks, usually before or alongside a human reviewer.
What is the code review bottleneck?
The code review bottleneck is the queue that forms when agents open pull requests faster than people can review them, so reviews slow down or get skimmed.
What is linting?
Linting is running a linter, a tool that checks source code against rules for likely bugs and style problems without running it, usually before review.
What is static code analysis?
Static code analysis is checking source code for bugs and security flaws without running it, usually with linters, type checkers, and security scanners.
What is technical debt, and do coding agents add to it?
Technical debt is the future cost of shortcuts in code or design, paid as slower changes and more bugs until someone cleans the shortcuts up.
How-to guides
How to review a pull request written by a coding agent
Reviewing an AI-generated pull request means checking its task, scope, tests, and evidence of a real run, not only reading the diff.
Comparisons
What is the difference between static and dynamic analysis?
Static analysis examines code without running it, while dynamic analysis observes the program as it runs, so each finds bugs that the other misses.
Common questions
Why does pull request size matter?
Pull request size affects review quality, because reviewers catch less as diffs grow, so large changes get skimmed and more defects reach the main branch.
Terms in this topic
- AI code review
- AI code review is a review practice that uses a language model to read a pull request or diff and comment on possible bugs, style problems, and risks.
- Code review
- Code review is a practice that has people or tools read a proposed code change before it merges, to catch defects, share knowledge, and keep the codebase consistent.
- Dynamic analysis
- Dynamic analysis is a method that observes a program while it runs, e.g. through tests, to find bugs that only appear at runtime.
- Linting
- Linting is a static check that compares source code against style and correctness rules with a tool called a linter, without running the code.
- Review bottleneck
- The review bottleneck is the queue that forms when code is produced faster than people can review it, so pull requests wait or get approved with less scrutiny.
- Static analysis
- Static analysis is a method that examines source code without running it, using rules and type information to flag likely bugs and security flaws.
- Technical debt
- Technical debt is the future cost of shortcuts in code or design, which a team pays as slower changes and more bugs until someone cleans the shortcuts up.