news.ycombinator.com

Ask HN: Does a human still review your code?

stikit · 9 points · 16 comments · 昨天

Most of the code I work on is for internal company use at a small company and for personal projects. After experiencing painful code review processes where code was rewritten several times for what many times felt like arbitrary reasons to fit someone’s idea of a best practice, I am now on a team where code review is largely automated. I find Claude’s /review and /code-review are invaluable and do a more thorough code review than any human . For those of you who use AI to write the majority of your code, do you still have a human in the loop to do more than spot checks ?

评论

5 条预览评论 · 正在加载完整讨论
shaftway昨天

Both. AI code review is built-in, but there's always a second human in the loop. I'm concerned that there are people pushing on the code generation front, the code reviewing front, and the laziness front. Eventually they're going to all meet in the middle, and there will be a significant number of engineers who are using AI to write and review the code, rubber stamp it, and push it into prod, with disasterous results.

joshstrange昨天

Personal/side-business: Almost fully automated PR review flow. Local agents review before PR, Github Actions runs Codex/Claude to review the PR, if everything passes (Unit, e2e, lint, etc) then I merge. I'll review critical code paths if they are touched but that's not too often. Day Job: Similar but more human-in-the-loop and we are still feeling out "what needs human review" and "agent review is good enough". LLM reviews have shown me/us that they will catch more things (legit things and silly things, to be fair) than human reviewers. Human reviewers are very bad at seeing what's _not_ there. Yes, humans will catch some things that the LLM won't but it's normally only on very custom things we've done that the LLM isn't "trained" on. [0] I think that as time goes on code reviews will be almost fully automated and humans will focus more on the plans before building, overviews of what was built, and other spec/diagram-type "artifacts" than looking at the actual code. [0] For my side projects and even a little for work I've been trending in the "do it the way the LLM wants" not "force it into the shape you thought of" because it's easier for the LLM to write/maintain/"understand". Similar to how I don't tell an LLM "put a red button on the page here that does X", I give it the problem I'm trying to solve so that I don't "bias" it to the way I first thought of. I may force it to do it "my way" in the end but I find I get exposed to new ideas or new/different ways to solve my problem when I don't "lead the witness".

ylynbuilds10小时前

It depends. Since I started coding with AI, I rarely review the code for my personal projects — I only run the code-review skill on critical features. But for internal company projects, we still run a strict code review tool, SonarQube, at build/release time to check code quality and security.

shanforge13小时前

Before coding agents, people generated code that was reviewable. Now, people generate entire features or 5K+ lines of changes in a single PR, fully introducing new functionality. We can’t defend ourselves against this and make production slow. But the only way forward is to start relying more on AI-based reviews. Here’s the interesting part: each PR gets reviewed by more than 3 people, each from their own perspective. Based on the questions and the affected paths, the reviewer directs the agent to focus on different points. Someone who is already familiar with the codebase can also guide the agent in the right direction. Recently, we also started automating UI reviews. The agent runs all the services, verifies the feature through the UI, takes screenshots, and uploads them directly to the GitHub PR. We call this UI Review. + Test coverage also improtant.

byra10小时前

Same as most others here, I think it depends so much on your use case. The speed you're as able to move at with no to lightweight manual code reviews is just so much higher, but there are cases where broken code could mess up critical prod systems so I don't see how you'd get rid of human code reviews there just yet. For personal usage I've found quick DeepSeek flash reviews a massive boon to finding obvious bugs though.