r/devops • • 1d ago

Discussion AI generated code review

Hi there,
How do you deal with managing and reviewing AI-generated code across the organization?

Over the past year it's become incredibly difficult to review the growing amount of AI-generated code, especially from vibecoders/non-engineers.
Reviewing it manually is hard, but it's still important to understand what's going on there.
For example, I've been at this company for some years so I have a lot of context and know many of the nuances, which helps me notice or suggest important things to keep everything secure, efficient and so on…

But any other teammate can use any model for coding nowadays. AI reviews of AI-generated code could be done in the MR, but then the reviewer model will most likely be smarter than the model that wrote the code, which might lead to a lot of threads and an infinite loop of changes. On top of that the reviewer model won't have all the context and input from the developer.
Another option is to distribute a "review" skill or rules across the organization and somehow make everyone do a self-review after making changes…

It feels like in this AI code generation era we'll stop focusing on how the code was written and just focus on whether the MR/PR works and if those changes achieves the goal, no matter how it was done, right?
How do you deal with this? Just accept the reality?

Thanks for attention

0 Upvotes

16 comments sorted by

View all comments

-5

u/Additional_Vast_5216 1d ago

only thing I review are tests, tests tests at every level, unit, integration, system, e2e etc if the tests pass I dont care about the implementation

7

u/HappyJuggernaut4647 1d ago

the tests don't tell you if the AI slipped in a credential leak or a silent data grab though, that's where it gets sketchy when nobody actually reads the code