Code Review: Dos and Don’ts of Code Review

Code Review

Here are some recommended practices and things to avoid during a code review:

Recommended Practices

  1. Clarity of Objectives:
    • Before starting a review, ensure you know what you are looking for. The review may focus on security, functionality, maintainability, or code style. Each aspect requires different attention and a specific approach.
  2. Collaborative Approach:
    • View code review as a collaborative activity rather than an opportunity to criticize. It is important to maintain a constructive dialogue with the person who wrote the code, providing useful feedback and proposing solutions whenever possible.
  3. Documentation of Conflicts:
    • If conflicts arise during the code review, ensure there is a defined process for resolving them. This may include consulting company guidelines or seeking an external opinion.
  4. Adequate Timing:
    • Do not rush the code review. While it is important to proceed with urgency, especially when other team members are waiting, it is essential to dedicate the necessary time to correctly identify security and functionality bugs.

Practices to Avoid in Code Review

  1. Constant and Unjustified Criticism:
    • Avoid finding flaws in the code just for the sake of it. If you constantly criticize without a valid reason, you risk losing credibility and creating a hostile work environment.
  2. Lack of Preparation:
    • Do not start a review without knowing the context of the code or the expectations regarding its function. An effective review requires a good understanding of the technical specifications and the coding standards adopted by the organization.
  3. Ignoring the Importance of Domain Knowledge:
    • A reviewer must have a good knowledge of the domain to which the code belongs. If you are not familiar with the specific area (e.g., compliance regulations or business risks), you risk missing important vulnerabilities.
  4. Not Defining Review Artifacts:
    • Ensure that the review produces the expected results, such as bug reports, security recommendations, or code fixes. Without a clear definition of what should emerge from the review, the process risks being ineffective.

These practices help ensure that code review is not only technical but also sensitive to human and collaborative aspects, promoting a healthy and productive development environment.

๐Ÿ”™ Back to the ISGroup SRL mini-series dedicated to Code Review!

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!