發布前審核 AI 輔助的程式碼變更
讓 AI 輔助的程式碼變更由清晰要求開始,經過安全及測試程序,最終由具明確責任的人員批准。
What you will produce
A reviewable result, not an automatic answer.
Follow the stages in order. Each stage ends with a tangible deliverable and a review checkpoint, so mistakes are caught before they become the next tool’s input.
在合適情況下使用免費方案;開始前請確認供應商目前的限制及價格。 Compare the latest verified AI pricing before buying another subscription.
Suggested stack
Tools used in this workflow.
The process matters more than the brand. Use an approved equivalent when it offers the controls and output quality your organisation needs.
Inputs and ownership
Before you start
- 受版本控制的程式碼庫、issue 及驗收標準
- 不包含正式環境機密資料的安全開發環境
- 一名了解受影響系統並獲授權的審核人員
Interactive workflow
Complete each stage in order.
Tick a stage only after its deliverable and review checkpoint are complete.
-
將要求轉化為驗收標準、受影響的元件、限制及預期的回復安排。
Deliverable可供審閱的工程工作簡報
Review checkpoint絕不能暴露登入憑證、客戶資料或正式環境設定。
-
要求 AI 助手先檢查相關程式碼並提出小範圍變更計劃,再開始生成程式碼。
Deliverable有明確範圍的實施計劃
Review checkpoint檢查每一行變更及每項依賴。
-
實施最小而完整的變更,只在需要解釋不明顯的決策時加入註解。
Deliverable聚焦的程式碼變更
Review checkpoint測試失敗路徑、權限及不可信輸入。
-
按風險程度執行適當的格式檢查、靜態分析、單元測試、整合測試、安全及回歸檢查。
Deliverable已記錄的驗證結果
Review checkpoint拒絕隱藏在變更中的無關重構。
-
發布前完成人工程式碼審核、部署審核、監察及回復準備。
Deliverable已批准的發布及回復計劃
Review checkpoint根據驗收標準監察部署後的實際行為。
Adapt, do not paste blindly
Working prompts for this recipe.
Replace bracketed placeholders, supply approved sources and remove unnecessary personal or confidential information.
工作 prompt
只有在替換所有方括號 placeholder 並移除不必要的敏感資料後才使用。
審閱以下程式碼任務及所提供的 repository 背景資料。先重新說明驗收標準,識別受影響的元件、安全邊界、測試及未知事項,然後提出最小變更計劃。在列出缺失資料前不要撰寫程式碼。保留範圍以外的現有行為,並絕不能要求或暴露機密資料。 任務: [TASK] 背景資料: [APPROVED CODE CONTEXT]
最終審核 prompt
作為第二輪檢查清單使用,並不代表已批准發布。
按照以下預期成果審閱草稿:讓 AI 輔助的程式碼變更由清晰要求開始,經過安全及測試程序,最終由具明確責任的人員批准。列出缺乏依據的陳述、缺失證據、含糊語言、私隱問題、無障礙問題,以及仍需人工批准的行動。在將問題分開列出之前,不要重寫草稿。
Human review required
Verification and cautions
- 使用前核實姓名、數字、引文及來源陳述。
- 除非所選服務及帳戶已獲批准處理相關資料,否則請移除機密或個人資料。
- 必須由一名指定人員對最終決策及已發布輸出承擔責任。
Keep the outcome, change the method
Practical alternatives
Continue with context