Lesson 13 / 25
Static Checks, Types and Builds
Cheap checks catch whole classes of errors.
Lint, type-check, build, scan
Beyond tests, run the project's linters, type checkers (mypy, TypeScript), build, and security scanners (dependency audit, static analysis) on every candidate. They catch unused variables, wrong types, unreachable code and risky patterns that tests may miss. Make the auto-fix pipeline use the same configuration as the project's CI so results agree, and never let a patch weaken lint or type settings to pass.
A verification gate list
All must pass for a candidate to advance.
gate example command pass condition
reproduction test python -m pytest tests/test_x.py::t passes (failed before)
full test suite python -m pytest -q all pass
lint ruff check . no new findings
types mypy src no new errors
build python -m build / npm run build succeeds
security pip-audit / npm audit, secret scan no new high findings
scope diff stats + protected paths within limitsCompare against the base branch
Judge "no new findings" relative to the base branch so pre-existing warnings do not block every fix.
Quick check: What should happen if a patch disables a lint rule to pass?
- Accept it as a fix
- Treat it as a protected change and reject it from automated fixing
- Prefer it over other candidates
- Ignore lint entirely
Answer
Treat it as a protected change and reject it from automated fixing — Do not weaken the checks.