Start
Starting audit and score
A scan of the codebase in P0-P3 order and a score for critical flows.
- Payment, login, data write paths
- Critical paths without tests
I read the code the team wrote and list findings by severity; we reproduce the bug in production and find its root cause; we deliver the fix together with a test that breaks when the fix is reverted.
With code inherited from someone else, I start with the path that touches the most money and data.
A green test alone is not proof. A test that does not break when the fix is reverted is not catching the bug.
Four findings in a made-up order function. Click the number on a line or a finding on the right.
Code review
A made-up example, 19 lines
export async function orderTotal(cart, coupon) { let total = 0; for (const item of cart.items) { total += item.price * item.quantity; } if (coupon) { total = total - total * coupon.rate; } const shipping = await shippingFee(cart.address); return Math.round(total + shipping);} app.post('/api/order', async (req, res) => { const { id, coupon } = req.body; const cart = await db.query( `SELECT * FROM cart WHERE id = ${id}`); const total = await orderTotal(cart, coupon); res.json({ total });});P0 lines 15-16
P0 lines 7, 14
P1 lines 4, 10
P2 line 9
The three packages that most often go with code support.
Start
A scan of the codebase in P0-P3 order and a score for critical flows.
Security
A review of secrets, personal data and third-party dependencies.
Speed
Code agents: a setup that writes on its own branch, is reviewed by a separate agent, and leaves the decision to the team.
Repository access can be discussed later; a short description of the bug and how long it has been happening is enough to start.