3 ms·
That's very true, but there's room for some nuance. Because of author inexperience, I wouldn't expect audits and reviews to be comprehensive, but I would expect
by speakingmoistly 7mo ago
That's very true, but there's room for some nuance. Because of author inexperience, I wouldn't expect audits and reviews to be comprehensive, but I would expect the questioning to take place. In the case of imports, it doesn't take years of experience to verify that the versions added are latest stable and to generally check out release notes / issues. It's far from enough, but it's something.
Also agreed on the cheaper-to-write bit. Trying to redeem piles of slop into something workable is a fool's errand.
- hsin003 7mo agoI think both points are true in practice. Reviewing AI-generated code can require more experience than generating it, but at the same time some basic checks (dependency versions, release notes, etc.) are still worth doing. One thing this incident reminded us of is that review is only a snapshot in time. Even if everything looks fine when a PR is merged, new CVEs can appear later and suddenly make previously safe dependencies vulnerable. That’s why we started treating monitoring and vulnerability checks as part of the platform itself, not just the review process.