| ▲ | MichaelNolan 4 hours ago | |||||||
Code metrics in general aren’t that widely used. I’ve only ever worked at one place (a bank) that tracked it, and that was only because sonarcube had it built in. While a lot of metrics make intuitive sense, we don’t have that much hard evidence to prove or disprove their value. Part of it is the whole “if a metric becomes a target, it ceases to be a good metric” thing. Adding the checks to a large existing project probably has negative value. But I think it’s worth doing for greenfield projects. For humans, these should just be advisory. But for LLMs I’m happy enough to make it a blocking check. I keep thinking of doing an experiment where I give the same LLM the same problem, and only change which metric is enforced. And then see if any of them have a noticeable effect on correctness/maintainability. > any examples of how people get this into an actual report / CI test / benchmark / whatever ? Yeah they have examples of adding it to CI, or local checks, generate html reports, etc in their docs. | ||||||||
| ▲ | paimapi 4 hours ago | parent | next [-] | |||||||
I think the future of development will be a lot of automated quality checks like these on AI-drafted code that humans review and ensures that it doesn't muck up the business logic and actually fulfills the acceptance criteria. that said, I don't think existing toolsets are really great at actually measuring code quality I've been in the process of reviewing and validating a lot of tools like this (qlty, Sonarqube, fallow, etc) and the false positive rate is anywhere from 20% to 80% for a lot of our sniff tests (zizmor produces an overwhelming majority of false positives here for what feels like arbitrary and very context-dependent GHA requirements) the last thing I want to do is to annoy the hell out of our devs by requiring checks like these to pass especially since it's only a small percentage of them who vibe code everything and then also vibe response to code reviews. I feel like that's the anti-pattern that we'd push people towards by requiring checks like these to pass another avenue of exploration has been requiring test coverage but also good test quality metrics (eg are there negative tests? mutation testing? empty asserts?) something that seems quite easy to spin up into a skill and pair with a deterministic harness. trash-tests is a neat little project that incorporates some of this: https://github.com/frangelbarrera/trash-tests (disclosure: I am not the repo owner or even a contributor, just a quality nerd who loves underdogs lol) all in all, it really does feel like we'll need a revamp of the SDLC with our current expected velocities | ||||||||
| ||||||||
| ▲ | sagenschneider 3 hours ago | parent | prev [-] | |||||||
Yep, this all actually started because of experimenting with my own open source project https://officefloor.net (giving full disclosure) I was testing the additive pipeline style of OfficeFloor against the mutative handler style of Spring. I was looking to see what factors could be used to allow AI to make long on going changes (experiment is 60 changes to an end point, where all add functionality and every 4th change is mutative on existing rules). Then I watch how AI manages to make the 60 changes in each architecture. I've done many runs and you are quite right about Goodhart effect in giving it the metric. Never knew Spring code could be written so badly. I've tried runs with better prompting also and I'm starting to find the key factor is actually the architecture itself. From my initial findings, it's seeming that additive pipeline architectures hold up much better against AI slop than our typically single method web handler architectures. | ||||||||