frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Ask HN: HN: Why do we code review?

1•abhisek•4h ago
This is not a click bait but I am really curious about revisiting the most obvious activity in SDLC - code review.

IMHO we code review to ensure quality, security and other guardrails beyond automated tools. There are also people aspect like mentoring and grooming junior engineers into best practices & new team members into coding standards and other conventions.

Let’s ignore the people aspect for a while. Linux Foundation survey says 70-90% of modern software constitute open source code. We only look at popularity, maintenance, known vulnerabilities of direct dependencies while adopting an open source dependency in our code base. We implicitly trust all the code brought in by transitive dependencies. I can confidently say my production projects has 50% or more code from open sources that I have no idea about.

We somehow assume that some magical database (CVE) will have all vulnerabilities in OSS code and tools like Snyk or Dependabot will take care of it. Who is responsible for running even a linter or a static analysis tool on an open source project and spending the time and effort in responsible disclosure with CVE.

Given this, is code review of internal code enough to trust quality & security of what we ship? Does anyone ever realistically considered reviewing OSS code used in your projects?

Comments

JohnFen•4h ago
> Given this, is code review of internal code enough to trust quality & security of what we ship?

No single thing is enough for this. Code review is an important part, though (assuming it's properly done, which it isn't in the vast majority of cases, it seems).

> Does anyone ever realistically considered reviewing OSS code used in your projects?

In spots, yes. As a whole, no. Depending on the size of the codebase, the time and effort required to do so would often change the economics such that it would be better just to develop the code in-house.

As an unimportant aside, I am skeptical of this assertion:

> Linux Foundation survey says 70-90% of modern software constitute open source code.

solaire_oa•3h ago
Revisiting code review in terms of how it functioned in 2020 seems antiquated.

Security and quality are a concern now that there's a flood of LLM barf that inexperienced engineers are liable to submit for code review. Code review has simultaneously never been more important and exhausting. If you (or anyone) suggest that we remove code review and accept the barf wave, I'd say FAFO.

Thoughts on the AI 2027 Discourse

https://dynomight.substack.com/p/ai2027
1•paulpauper•42s ago•0 comments

Childhood and Education #10: Behaviors

https://thezvi.substack.com/p/childhood-and-education-10-behaviors
1•paulpauper•1m ago•0 comments

When Can I Stop Listening to My Enemy's Points?

https://substack.com/home/post/p-166684398
1•paulpauper•4m ago•0 comments

Show HN: Letter Lockbox – A word game I built over the weekend with Claude Code

https://www.letterlockbox.com
1•christensen143•4m ago•0 comments

Programmers and Their Blogs

https://lambdaland.org/posts/2025-06-24_reading_blogs/
1•ashton314•4m ago•0 comments

Ask HN: What's your fastest conversion from cold outreach to prepaid client?

1•iamarsibragimov•5m ago•0 comments

Namespaced Pundit Policies Without the Repetition Racket

https://alec-c4.com/posts/2025-06-24-pundit-namespaced-policies/
2•alec-c4•7m ago•1 comments

The Legacy of "The Gastronomical Me"

https://lithub.com/fidelity-to-both-pleasure-and-humiliation-on-m-f-k-fishers-feminist-realism/
2•spewil•8m ago•0 comments

Show HN: How Usage Works

https://www.usage.ai/blog/how-usage-works
4•kavehkhorram•9m ago•0 comments

Why Your Car's Touchscreen Is More Dangerous Than Your Phone

https://www.carsandhorsepower.com/featured/your-fancy-car-s-touchscreen-is-worse-than-buttons-and-studies-prove-it
2•m463•9m ago•0 comments

Dr. Dobb's

https://drdobbs.com/
2•johnnyApplePRNG•10m ago•0 comments

Joining CNCF as Executive Director: Let's Build What's Next

https://www.cncf.io/blog/2025/06/24/joining-cncf-as-executive-director-lets-build-whats-next/
3•bretpiatt•11m ago•0 comments

Elisa: A Comprehensive Guide to Enzyme-Linked Immunosorbent Assay

https://www.clyte.tech/post/mastering-elisa-a-comprehensive-guide-to-enzyme-linked-immunosorbent-assay
2•mw2taba88•16m ago•1 comments

Secure your Express application APIs in 5 minutes with Cedar

https://aws.amazon.com/blogs/opensource/secure-your-application-apis-in-5-minutes-with-cedar/
1•idm_guru•18m ago•0 comments

Why Paris's Centre Pompidou, not even 50 years old, must close for five years

https://www.lemonde.fr/en/opinion/article/2025/06/19/why-the-centre-pompidou-not-even-50-years-old-must-close-for-five-years_6742490_23.html
1•PaulHoule•21m ago•1 comments

Curated realities: An AI film festival and the future of human expression

https://arstechnica.com/culture/2025/06/curated-realities-an-ai-film-festival-and-the-future-of-human-expression/
1•rntn•21m ago•0 comments

Scientists can now target the cells at the center of ALS

https://alleninstitute.org/news/scientists-can-now-target-the-cells-at-the-center-of-als/
1•gmays•22m ago•0 comments

Haflang: Hardware Acceleration of Functional Languages

https://haflang.github.io/
1•fanf2•26m ago•0 comments

Waldo – Geoip Lookups

https://geoip.dpdns.org/
1•metalshanked•29m ago•0 comments

David Friedberg: it is important for America that Mamdani get elected

https://twitter.com/friedberg/status/1937593902456099315
1•donsupreme•33m ago•1 comments

Portable Network Graphics (PNG) Specification (Third Edition)

https://www.w3.org/TR/png-3/
1•trothamel•34m ago•0 comments

EU lawmakers vote to bar carry-on luggage fees on planes

https://www.france24.com/en/live-news/20250624-eu-lawmakers-vote-to-bar-carry-on-luggage-fees-on-planes
3•gnabgib•36m ago•1 comments

I Designed UX for an AI Product Last Year. Are Those Lessons Still Valid?

https://uxdesign.cc/ai-ux-design-for-intelligent-interfaces-bc966e96107d
1•antarabasu•37m ago•1 comments

The Sun is twisting Mercury's crust in unexpected ways

https://bgr.com/science/the-sun-is-twisting-mercurys-crust-in-unexpected-ways/
2•Bluestein•38m ago•0 comments

How to (Almost) solve cybersecurity once and for all

https://adaptive.live/blog/how-we-can-almost-solve-cyber-security-once-and-for-all
1•debarshri•39m ago•0 comments

I Love GitOps

https://newsletter.masterpoint.io/p/i-love-gitops
1•mooreds•39m ago•0 comments

What It's Like to Be 'Mind Blind'

https://time.com/6155443/aphantasia-mind-blind/
2•mucha•42m ago•0 comments

Embabel: Framework for Building AI Agents with Java

https://thenewstack.io/meet-embabel-a-framework-for-building-ai-agents-with-java/
3•andrewstetsenko•42m ago•0 comments

Epic Games and Qualcomm Are Bringing Fortnite to Windows 11 on Arm

https://www.thurrott.com/games/318482/epic-games-and-qualcomm-are-bringing-fortnite-to-windows-11-on-arm
1•mooreds•43m ago•0 comments

Marginalia mania: how 'annotating' books went from no-no to BookTok's next trend

https://www.theguardian.com/books/2025/jun/23/marginalia-mania-how-annotating-books-went-from-big-no-no-to-booktoks-next-trend
2•herbertl•44m ago•0 comments