Chapter 12 · CLI
Review: code review, security review and scans
Claude Code can review code at several levels: a regular change review, deep code review, a security scan and tools like ultrareview for bug hunting. A structured review before merging prevents incidents.
Video
Steps
- Run a review on the diff before merging to catch logic, style and convention issues.
- A security scan looks for dangerous patterns in code: injections, embedded secrets and problematic dependencies.
- ultrareview and similar tools hunt bugs more methodically than a regular review; use them before release.
- Treat findings as suggestions: verify each against the context before changing, because automated review errs too.
Common pitfall: A clean security scan is not proof the code is safe; it is one layer alongside tests, human review and business logic.
Hands-on exercise: Run a review and security scan on an existing branch in your project. Record three findings and check whether each is real or a false positive.
Filmed demo · Video is added in the media phase
Recap
Comprehension check
How should you treat automated review findings?
Recap
- Review before merging, not after
- A security scan is one layer
- Verify findings before changing