Testing & Quality
Treat AI output like a talented junior developer's pull request: promising, fast, and unverified. AI code is an input to your quality process, not an output of it — don't trust, verify, and read every line.
Your quality stack still matters
| Layer | What it does | With AI in the loop |
|---|---|---|
| Tests | RSpec, Jest, pytest — prove behavior, catch regressions. | Coverage targets unchanged. Ask the AI for happy and sad paths — it will skip the sad ones unless you ask. |
| Linters | ESLint, RuboCop — consistency and common-error catches. | Wire into pre-commit hooks so AI-generated code meets your standards before it lands. |
| Static analysis & secret scanning | GitHub Advanced Security — flaws and committed credentials. | Already part of the ND standard stack. Treat findings as real until proven otherwise. |
| Dependency analysis | Dependabot and supply-chain review. | Extra important: AI-scaffolded projects arrive with dependencies you didn't consciously choose. |
| Vulnerability scanning | OWASP-style scans of the running app. | Don't be the team that bypasses them because “the AI's code looked clean.” |
The bar goes up, not down
AI doesn't relax the quality bar — it raises it. You're shipping more code per hour, so the percentage that gets meaningfully quality-checked has to stay high or your risk grows exactly as fast as your velocity. The habits that keep it high:
- Tests land with the code, not after. The core workflow makes “tests + docs” its own phase — don't let it fall off the end.
- Make the AI test its own work. “Write the tests for this — include edge cases and failure modes” then read them skeptically: a test that can't fail isn't a test.
- Run everything locally before the PR. Lint, test, scan — the pre-commit commands belong in your context file so the AI runs them too.
Passing quality checks gets code to the door; human review is still the last gate. That's the next page: Shipping & review.