Code, commit, celebrate!
We're excited to announce that @reviewpad is joining @snyk to help developers stay secure without slowing down! Check out the announcement blog for more info!
https://t.co/KMrq37lLSl
Code, commit, celebrate!
We're excited to announce that @reviewpad is joining @snyksec to help developers stay secure without slowing down! π π»
Check out the announcement blog for more info. π
https://t.co/F98Q6mC6q0
@FreddyMallet dives deep into three checks of our newly launched Reviewpad Check. Discover how these can help you and your team be more productive!
Read the blog post here: https://t.co/oehYU5ad9j
@dependabot and @renovatebot are pretty useful to update dependencies but can lead to a huge number of open PRs.
Check out how you can use @reviewpad to supercharge those PRs ππππ
In only 41 LOC of our DSL, you can:
- Specify when a PR only touches dependencies with file extension groups;
- Specify when a PR touches high risk dependencies through queries over the diff;
- Automatically merge PRs that only update low-risk dependencies if the build passes;
- Automatically assign the right developers to PRs if the build fails.
Crush those open PRs!
https://t.co/hVwvRbHM1J
Erroneous string manipulation is the main source of security vulnerabilities. I saw it in js eval, sql injections and now we have a new culprit in prompt injection.
GPT-4 based AI agents capabilities on code explainability are incredibly useful for pull requests. Here's an example on a @reviewpad PR. For someone that has been doing static analysis for a long time, these are really exciting times!
Pull request debt is real. Iβve seen it in countless teams over the past years. A long list of open pull requests which will never be merged. Reminds me of the old cars in the dealership that are just becoming more and more of a liability.
Weekly reminder that pull request experience on vanilla @github still sucks. Lots of talk about improving developer experience but very little to show for. If we spent the amount of resources on reducing CI times by 10% on it, the impact would be tremendous.
GPT-4 cost a lot more than GPT-3 to train. If it was worthwhile, that should show up in previously-infeasible products now being possible. Curious to see the replies!
I've seen a lot of teams using checklists on pull requests without a way of enforcing them. Here's a demo where I use @reviewpad to protect merges from happening when the checklists are not completed: https://t.co/RrD0uyQtLN