Read theDiff

What happened today in AI-assisted software development.

Byline

Hal Brackett

Editor · they/them

Coding agents, vibe coding, and the review problem

I have been shipping software since 2004. Perl, then Java I did not enjoy, then a long stretch of backend work nobody will ever write a blog post about. These days I write most of my code with an agent in a terminal, and I read every line before it lands.

That puts me in an awkward middle. I am not a sceptic — the tools are genuinely good now, and I would not go back. I am also not a believer, because I keep finding the failure modes, and the failure modes are interesting.

A few things I think are true, offered so you know my bias:

  • The bottleneck was never typing. It was understanding, and it still is.
  • Review is the new writing. We have not built the tools or the habits for that yet, and it shows.
  • "It compiles and the tests pass" was always a weak signal. It is now an actively misleading one.
  • Most productivity numbers in this space, in both directions, are measuring something other than what they claim to measure.

30 posts

  1. #0035 Review stopped being the only guardrail arXiv
  2. #0034 Confident and wrong looks exactly like confident and right arXiv
  3. #0032 A few pages of markdown, and half the complexity growth arXiv
  4. #0031 Ten minutes from pull request to probe Anil Madhavapeddy
  5. #0030 The classifier blocked the cleanup, not the malware Embrace The Red
  6. #0027 Two percent of the runs noticed anything wrong arXiv
  7. #0026 The screenshot test caught a state bug arXiv
  8. #0024 The router was not the point arXiv
  9. #0023 One click, and the assistant did the rest Infosecurity Magazine
  10. #0022 Eighty-seven comments, and nobody answered the question r/vibecoding
  11. #0020 The attestation was valid. That was the problem. Snyk
  12. #0019 Forge, and the number that moved GitHub
  13. #0018 39% of the score belongs to the backend arXiv
  14. #0017 Code nobody read, that you can trust anyway GitHub
  15. #0016 One hour to a prototype, a hundred to a product Mac Budkowski
  16. #0015 An ext4 driver arrived at OpenBSD with no author LWN
  17. #0014 Seven hours, $400 of tokens, 13,000 lines of Go Reco
  18. #0013 We wave through a third of the malicious requests The Register
  19. #0012 Rootly gave up on small pull requests InfoQ
  20. #0011 Spotify moved the bottleneck and said so InfoQ
  21. #0010 npm puts a human back in front of the registry InfoQ
  22. #0009 119 developers on what the habit has done to them arXiv
  23. #0008 Review is the new writing
  24. #0007 Good Vibrations: somebody studied the joy arXiv
  25. #0006 The 19% slowdown study, revisited by the people who ran it METR
  26. #0005 DORA puts a number on the tuition InfoQ
  27. #0004 Asking the model to "make it more secure" five times makes it less secure arXiv
  28. #0003 Somebody is finally counting the CVEs Infosecurity Magazine
  29. #0002 GitHub ponders a kill switch for pull requests The Register
  30. #0001 Diff #0001

Hal Brackett is a pen name — about this site →