search
code reviewers
Trends
- 1Apple Products Hit by Remote Code Execution VulnerabilityβApple Products Remote Code Execution Vulnerability
Security authorities have issued an alert over a remote code execution vulnerability affecting Apple products, warning users that attackers could potentially run malicious code on affected devices. Apple is expected to address the flaw through a software update, and users are advised to install patches promptly and review official advisories for affected models and versions.
- 2Solus Linux Adopts Formal Policy for AI-Assisted CodeβSolus Linux now allows AI-assisted code contributions under strict disclosure, testing, and accountability requirements.
The Solus Linux distribution has formally adopted a policy allowing AI- and LLM-assisted code contributions, but only under strict conditions. Contributors must disclose AI use, ensure code passes testing and review, and remain accountable for what they submit. The move makes Solus one of the more explicit open-source projects in setting formal rules for AI-generated contributions.
- 3Massive open-source pull request sparks AI slop debateβOk, this got to be a repo diff record. +238,856 -260 https:// github.com/saga-soft/novelWrit er/pull/3067 # AI # Slop #
A pull request on the open-source project novelWriter by saga-soft is drawing attention for its sheer scale: roughly 238,856 lines added against just 260 removed, a size developers are calling a possible repo diff record. Commenters suspect bulk AI-generated code, tagging it as "AI slop", and are debating whether maintainers can meaningfully review changes of this magnitude.
- 4
Developers are voicing strong approval for OpenAI's Codex app, calling it one of the best AI coding tools available. The conversation highlights how the app helps programmers write, review, and debug code faster, with many comparing it favorably to rival assistants. Discussion centers on its practical usefulness in daily development workflows rather than hype, suggesting growing adoption among working engineers.
- 5
Google engineer Addy Osmani has published a new open-source repository, agent-skills, described as production-grade engineering skills for AI coding agents. The JavaScript project is gaining traction on GitHub, drawing attention from developers interested in improving how AI agents write, review and maintain real-world code. It adds to a growing wave of tooling aimed at making coding agents more reliable in production environments.
- 6
Apple has announced changes to how Full Disk Access works in macOS, according to a notice posted on its developer news site. The update affects how apps request access to protected user data such as files, mail messages and browser history. Developers are being asked to review the new requirements, and the change is drawing attention from engineers discussing the privacy and security implications.
- 7Greg Kroah-Hartman on software security in the LLM eraβGreg Kroah-Hartman β Security in the LLM Age [video]
Linux kernel maintainer Greg Kroah-Hartman is featured in a talk examining how large language models affect software security. He discusses what AI-generated code means for kernel maintenance, vulnerabilities, and the review process, arguing that established development practices matter more as machine-written contributions grow.
- 8Insignary Launches Clarity AIR to Detect Undeclared CodeβInsignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
Security firm Insignary has launched Clarity AIR, a tool designed to identify undeclared open-source components and AI-generated code within software projects. The product aims to help organizations understand what is actually inside their codebases, addressing growing concerns over hidden dependencies, licensing risks and unvetted AI-written code entering production without proper review.
- 9Perspica launches as a semantic diff tool for code reviewβShow HN: Perspica β A semantic diff for reviewing code
Developer sshah03 has released Perspica, an open-source tool that produces semantic diffs of code, aiming to make code review easier by highlighting meaningful changes rather than raw line differences. The project, available on GitHub, is being shared with the Hacker News community for feedback, with early readers debating how semantic diffing compares to conventional diff tools.
- 10Harvard Physicist Uses AI to Crack 400 Scientific Problems in MonthsβHarvard Physicist Teams with AI to Solve 400 Scientific Problems in Three Months
A Harvard physicist reports that, working alongside artificial intelligence tools, he solved 400 scientific problems in three months β a pace he credits to AI handling calculations, literature review and code while he directed the research. Commenters are split: some call it proof that AI can dramatically accelerate real science, others question how rigorous the problems were and whether the results can be independently verified.
- 11System76 bans LLM-generated code in COSMIC projectsβΌSystem76 COSMIC projects will no longer accept LLM-generated content in code submissions
System76 has announced that its COSMIC desktop projects will no longer accept code submissions containing LLM-generated content. The Linux hardware and software developer says contributions must be written without AI assistance. The move reflects a growing frustration among open source maintainers, who argue that machine-generated code adds review burden and quality problems while contributors submit pull requests that are difficult to verify or maintain.
- 12Orbi AI agent turns GitHub issues into merged pull requestsβΌOrbi takes a GitHub issue and hands back a reviewed, merged pull request. One agent writes the fix,... # ai # opensource
Orbi, an AI coding agent, reportedly takes a GitHub issue and returns a reviewed, merged pull request, with one agent writing the fix and another handling review. A follow-up post examining the system's harness asks what its reviewer missed, suggesting developers are scrutinising how reliable the automated pipeline is. The discussion is drawing interest from the open-source and AI engineering communities.
- 13
OpenAI has made its automatic code review feature free for all Codex users. The tool reviews code changes automatically, giving developers feedback without a paid tier. The move is being discussed as a way to pull more developers into OpenAI's coding ecosystem at a time when automated code review and AI coding assistants are a highly competitive market.
- 14
Memes about 'vibe coding' β building software by prompting AI models and accepting generated code without close review β are circulating widely among developers, sparking a fresh debate over whether AI-assisted programming is a legitimate productivity boost or a shortcut that produces unverified, fragile code. Supporters joke about shipping features without reading the output, while critics warn the practice risks quality, security and maintainability as more teams adopt AI code generation tools.
- 15Developer says Claude Code now writes most of his codeβA year ago most of my day was typing code. Today Claude Code types most of it, and my day is... # ai # productivity # op
A software developer reports that a year ago most of his working day was spent typing code, but today the AI coding tool Claude Code writes most of it. He says his role has shifted to reviewing and directing, and describes building an IDE designed for the part of the work that remains. The post has struck a chord with other programmers weighing how AI agents are changing daily development work.
- 16Pop!_OS bans AI-generated code from its codebaseβPop!_OS bans AI-generated code from much of its codebase
System76, the company behind the Pop!_OS Linux distribution, has banned AI-generated code across many of its COSMIC codebases, the desktop environment underpinning the operating system. The decision bars contributions written by AI tools from large parts of the project, with developers expected to write and review code themselves. The move is drawing attention and debate among open-source developers weighing code quality, licensing and trust issues around AI-assisted programming.
- 17CodeDiff tool launched promising sub-100ms syntax-aware diffsβShow HN: CodeDiff β Fast (<100ms), robust (99.95%) syntax-aware code diff
A developer has released CodeDiff, an open-source code comparison tool that claims to produce syntax-aware diffs in under 100 milliseconds with 99.95 percent robustness. The tool is available on GitHub and is being presented to the Hacker News community for feedback and scrutiny.
- 18New Emacs tool hutch brings local code reviews to MagitβΌhutch: local code reviews in emacs for the mildly disenfranchised https://kitallis.in/p/hutch-a-local-code-review-interf
Developer Kitallis has released hutch, an Emacs interface for doing local code reviews within Magit, aimed at developers who prefer reviewing code without leaving their editor or relying on hosted platforms. The tool is being shared among open-source communities, where it has drawn modest attention from Emacs and programming enthusiasts interested in lightweight, editor-based review workflows.
- 19oh-my-agent project brings automated code project reviews to Linux communityβProjekte oh-my-agent: ProjektprΓΌfungen mit dem bisherigen Code-Agenten nutzen https:// forum.ubuntuusers.de/topic/oh- my
A new project called oh-my-agent has been presented on the German Ubuntu users forum, describing how existing code agents can be used to carry out automated project reviews. The thread, published under the Linux and open source sections, explains how developers can apply the tooling to check their current codebases. Responses so far appear limited, with the discussion still in an early stage.
- 20Crypto Community Urges Caution Before Interacting With Smart ContractsβΌAt Cryptonegar, we spend a lot of time looking at crypto projects, and one thing that is easy to... # blockchain # crypt
A crypto commentary outlet is drawing attention to the basics of checking a smart contract before interacting with it, flagging security, coding quality and community openness as key things to review. The advice comes as crypto users continue to lose funds to flawed or malicious blockchain projects. Readers are being reminded that simple due diligence on code and developers can prevent costly mistakes.
- 21Developer ditches code review for AI agents, tries new approachβI stopped reviewing my agents' code. Here's what I do instead Article URL: https:// alexeyindeev.substack.com/p/i- stopp
Engineer Alexey Indeev has written that he no longer reviews code produced by his AI agents, and describes the alternative workflow he uses instead in a Substack essay. The piece has drawn modest attention on Hacker News, where developers are weighing whether traditional code review still makes sense as more work is delegated to autonomous coding agents.
- 22AI code review reports arrive before humans even open the PRβPicture this, you open a PR and the AI report is already waiting. Three findings, all minor. You skim... # codereview #
Developers are discussing the growing normalisation of AI-generated code review, where an automated report is already waiting when a pull request is opened β in the example, three minor findings and an approval. The debate centres on whether these instant AI verdicts add value or create a false sense of scrutiny, with critics noting code can be approved without anyone truly understanding it.
- 23Meta patched Muse VM escape vulnerability ahead of launchβΌMeta Rushed to Fix a Muse VM Escape Vulnerability Before Launch
Meta moved quickly to fix a virtual machine escape vulnerability in its Muse system before the product launched, according to a report by Gadget Review. A VM escape flaw would let malicious code break out of a sandboxed environment and access the host system, making it a serious security concern. The fix suggests the issue was identified during pre-launch testing, though details on severity or discovery remain limited.
- 24Is there a telltale signature of AI-written code?βPeople like to complain about AI code. But what really sets it apart? Is there a common signature that separates AI code
Debate is under way among developers over whether AI-generated code has a recognizable signature that separates it from human-written code. While complaints about AI code quality are common, programmers are now discussing what stylistic or structural patterns, if any, actually distinguish it. The conversation frames the question as a testable hypothesis, reflecting wider concerns in the software community about code quality, review practices and how to handle the growing volume of machine-assisted development work.
- 25Developer proposes visual interfaces for AI agent outputβBecause I find it difficult to read the textual output of agents after each modification or... # webdev # ai # programmi
A developer is voicing frustration with the text-heavy output of AI coding agents after each code modification, saying it is difficult to read in web development workflows. The proposal gaining attention is to give agents chalkboard-style and avatar-based interfaces, making changes easier to scan and more inclusive for developers reviewing automated edits.
- 26AI code generation speeds ahead of open source developersβΌAI can generate code faster, but can open source keep up?
Discussion is growing around whether open source software projects can keep pace with AI tools that generate code far faster than human developers. The concern centres on how volunteer-driven communities, which maintain much of the world's critical software infrastructure, will absorb or compete with automated code production while still ensuring quality, security and proper review.
- 27AI-generated song about AI code reviews goes viralβWith great irony, AI made a banger song... about AI. βΆοΈ LGTM (Looks Good to Me) - Claude Opus 5.5 music video https:// y
A new music video titled 'LGTM (Looks Good to Me)', created with AI and associated with Anthropic's Claude model, is circulating online. The satirical song plays on the phrase developers use to approve code, poking fun at AI-assisted programming and the habit of rubber-stamping machine-generated work. Commenters are enjoying the irony of an AI producing a catchy track about AI.
- 28Pinrail launches as desktop inbox for reviewing coding agentsβShow HN: Pinrail - A desktop inbox where coding agents wait for your review https://github.com/forgeplane/pinrail # Hack
A developer has released Pinrail, an open-source desktop application that works like an inbox where AI coding agents pause and wait for human review before their changes proceed. The tool, shared on Hacker News under the Show HN banner, is available on GitHub under the forgeplane account and targets developers juggling multiple agent-run tasks at once.
- 29Developers ask which AI models handle code security reviewsβAsk HN: Which frontier model can do code security reviews
A question on Hacker News is asking which frontier AI models are capable of performing code security reviews. The discussion seeks recommendations on which large language models can reliably audit code for vulnerabilities. With few replies so far, the thread reflects a broader interest among developers in using AI tools for security analysis.
- 30AI Now Writing Code That Humans Can't Even UnderstandβΌAI Now Writing Code That Humans Canβt Even Understand
Futurism reports that AI systems are now producing computer code that human programmers cannot understand or reliably verify. The concern is that as models generate increasingly complex solutions, developers may ship software whose logic no one fully grasps, raising questions about debugging, security, and accountability. The story taps into a wider debate about losing human oversight as machine-written code becomes more common in real-world software.
- 31Hands-On With OpenAI's New Codex Desktop AppβI Tested OpenAI's New Codex Desktop App. The UI Is the Real Product I started the way I... # ai # openai # programming #
A developer has published a first-hand review of OpenAI's new Codex desktop application, concluding that the user interface is the real product rather than the underlying coding model. The write-up walks through the reviewer's initial experience using the app and argues OpenAI is putting significant weight on design and workflow. It lands amid heavy developer interest in AI coding tools and OpenAI's expanding product line.
- 32AI agents with self-healing scripts reshape software testingβSelf-healing keeps every script alive. Let an AI agent run your plain-language test cases in a headless browser instead,
Software testers are discussing a workflow where an AI agent runs plain-language test cases in a headless browser, using self-healing to keep scripts working as applications change, while only scenarios worth keeping long-term get promoted into maintained code. Supporters say it cuts maintenance burden on QA teams; others caution that AI-run tests still need human review before being trusted in release pipelines.
- 33Critical LightLLM flaw exposes AI servers to remote code executionβπ¨ CVE-2026-103041 β CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache
A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.
- 34AI Agents Drive Developer Shift from Go to RustβAI Agents Make Rust the Go-To Choice Over Go for Dev Teams
Developer teams are increasingly choosing Rust over Go for new projects, with AI coding agents cited as a driving factor. The argument is that AI assistants write safer, more correct code in Rust because the compiler catches errors that would slip through in Go, reducing the need for manual review. Some developers agree, while others argue Go's simplicity still makes it more productive.
- 35SwiftFairy update speeds up AI code reviews on macOSβJust pushed an update to SwiftFairy π§, our native macOS MCP server that reviews your agentβs code locally for correctnes
Developer hishnash has released version 2026.10.1 of SwiftFairy, a native macOS MCP server that reviews AI agents' code locally for correctness, performance and maintainability. The update lets agents send file paths instead of full source code, making large reviews faster. It is a small but notable release for developers running AI coding agents on Macs, reflecting growing interest in local, privacy-friendly tooling.
- 36Developer cuts AI code review noise by a thirdβAI code review has a noise problem. On a public benchmark of 50 real pull requests, CodeRabbit raised... # ai # coderevi
A developer has published findings that CodeRabbit, a popular AI-powered code review tool, produces excessive noise when reviewing real pull requests. On a public benchmark of 50 genuine pull requests, the tool flagged far more issues than necessary, and a modification reduced its review noise by roughly a third. The work has sparked discussion among developers about whether AI review tools create too many low-value comments that slow teams down.
- 37Five lessons from running Claude Code as an hourly agentβ5 lessons from running an hourly Claude Code cloud agent on a large production monorepo: proving review comments, loop p
An engineer has shared five lessons from running Anthropic's Claude Code as a cloud agent every hour on a large production monorepo. The write-up covers validating review comments, preventing the agent from getting stuck in loops, fixing a 403 error, and reducing token consumption. The post is drawing attention from developers interested in using AI coding agents for automated code review in real production environments.
- 38IBM's AI clearinghouse uncovers hundreds of Java flawsβIBMβs AI-powered vulnerability clearinghouse finds hundreds of Java flaws
IBM's AI-powered vulnerability clearinghouse has identified hundreds of security flaws in Java software. The finding highlights the growing role of artificial intelligence in scanning open-source code for vulnerabilities at scale, giving developers advance warning of weaknesses that attackers could exploit. Security teams are expected to review the affected Java components.
- 39Coreboot 26.09 Adds Framework Laptop 12 SupportβΌCoreboot 26.09 Released With Framework Laptop 12 Support, AI Review Comment Policy
The open-source firmware project Coreboot has released version 26.09, adding support for the Framework Laptop 12 and introducing a new policy on AI-generated comments in code reviews. The release matters to users who want open firmware alternatives to vendor BIOS on recent hardware, particularly the modular laptop maker's latest device.
- 40GitHub launches ReviewBench, an open benchmark for AI code reviewβΌReviewBench: An open benchmark for AI code review
GitHub has introduced ReviewBench, an open benchmark for measuring how well AI models perform code review. The benchmark is intended to give developers and researchers a standard, reproducible way to compare the quality of AI-generated code review feedback, as AI assistants are increasingly used in real software development workflows.
Repos
- mvschwarz/openrig Build your own network of agents from Claude Code, Codex and Pi: persistent teams with roles, shared context and owned w
- edenfunf/reelmimic Show it a video you love. Get a new video in the same style. An AI crew (Claude Code or Codex) plans, builds and reviews
- echris6/motion-video-kit Claude Code skill kit for premium AI-assisted business videos: independent critic loop, motion principles from 28 launch
- michael-denyer/pstack-claude Claude Code, Codex, Copilot, Pi, OpenCode, Gemini, and Prime Agent versions of Poteto's pstack. Rigorous agent work
- egma-ai/jev-code-reviewer Review behavior, not just diffs. Jev prioritizes human attention; OpenAI explains the changes. Local CLI + agent skill +
- cursor/plugins Cursor plugin specification and official plugins
- addyosmani/agent-skills Production-grade engineering skills for AI coding agents.
- obra/superpowers An agentic skills framework & software development methodology that works.
- garrytan/gstack Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Man
- anthropics/claude-code-action
- sshah03/perspica Review code changes by what they do, not line by line.
- ethanplusai/astra-flash-orchestrator Coordinate your models from Codex. Plan, delegate, use host tools, and review work across workspaces. Formerly Astra Fla
- forgeplane/pinrail Human in the loop for agentic workflows
- devagrawal09/jev-review A staged code-review workflow and local dashboard built with TypeSafe Jev.