3 ms·
I think some folks are very quick to drop rigor and care as "traditional practices" as if we're talking about churning butter by hand. One thing that might be v
by speakingmoistly 7mo ago
I think some folks are very quick to drop rigor and care as "traditional practices" as if we're talking about churning butter by hand. One thing that might be valuable to keep in mind is that LLM tooling might feel like an expert, but generally has the decisionmaking skills of a junior. In that light, the rigor and best practices that were already (hopefully) part of software engineering practice are even more important.
> In traditional development, you review versions carefully. With AI-generated scaffolding, that step is easy to overlook.
If in "traditional development", everything is reviewed carefully, why wouldn't it be when some of the toil is automated? If anything, that's exactly what the time that's freed up by not having to scaffold things by hand should be invested in: sifting through what's been added and the choices made by the LLM to make sure they are sound and follow best practices.
- hsin003 7mo agoTotally agree — AI scaffolding automates work, but best practices like CI/CD and pentesting are still essential. Continuous monitoring is necessary for all commits, and combining it with a dev-like centralized platform ensures every service and endpoint stays safe.
- speakingmoistly 7mo agoCI/CD and security audits are activities that help with confidence and kicking the tires after development takes place, but the practice that's really needed here is scrutiny and review from the author of the change and from non-author peers while code is being put together. I'd go further and say that if the intent is to produce a production-ready, secure and well-designed and implemented solution, it cannot be vibe-coded. A prototype that de-risks the design and that gets trashed before implementation begins would be the right place for vibing.
- veunes 7mo agoReviewing generated code actually takes a higher skill level than writing it. A junior who prompted this Next.js app into existence is physically incapable of auditing the security of those imports. And for a senior it's often cheaper to just write it from scratch than to sit there and audit abstract spaghetti generated by Claude
- speakingmoistly 7mo agoThat's very true, but there's room for some nuance. Because of author inexperience, I wouldn't expect audits and reviews to be comprehensive, but I would expect the questioning to take place. In the case of imports, it doesn't take years of experience to verify that the versions added are latest stable and to generally check out release notes / issues. It's far from enough, but it's something. Also agreed on the cheaper-to-write bit. Trying to redeem piles of slop into something workable is a fool's errand.
- hsin003 7mo agoI think both points are true in practice. Reviewing AI-generated code can require more experience than generating it, but at the same time some basic checks (dependency versions, release notes, etc.) are still worth doing. One thing this incident reminded us of is that review is only a snapshot in time. Even if everything looks fine when a PR is merged, new CVEs can appear later and suddenly make previously safe dependencies vulnerable. That’s why we started treating monitoring and vulnerability checks as part of the platform itself, not just the review process.