Lesson 13 / 25

Static Checks, Types and Builds

Cheap checks catch whole classes of errors.

Lint, type-check, build, scan

Beyond tests, run the project's linters, type checkers (mypy, TypeScript), build, and security scanners (dependency audit, static analysis) on every candidate. They catch unused variables, wrong types, unreachable code and risky patterns that tests may miss. Make the auto-fix pipeline use the same configuration as the project's CI so results agree, and never let a patch weaken lint or type settings to pass.

A verification gate list

All must pass for a candidate to advance.

gate                         example command                     pass condition
reproduction test            python -m pytest tests/test_x.py::t  passes (failed before)
full test suite              python -m pytest -q                  all pass
lint                         ruff check .                         no new findings
types                        mypy src                             no new errors
build                        python -m build / npm run build      succeeds
security                     pip-audit / npm audit, secret scan   no new high findings
scope                        diff stats + protected paths         within limits

Compare against the base branch

Judge "no new findings" relative to the base branch so pre-existing warnings do not block every fix.

Quick check: What should happen if a patch disables a lint rule to pass?

  • Accept it as a fix
  • Treat it as a protected change and reject it from automated fixing
  • Prefer it over other candidates
  • Ignore lint entirely
Answer

Treat it as a protected change and reject it from automated fixing — Do not weaken the checks.