發布前審查 AI 輔助的程式碼變更
讓 AI 輔助的程式碼變更從明確需求開始,經過安全性與測試檢查,再由具明確責任的人員完成核准。
What you will produce
A reviewable result, not an automatic answer.
Follow the stages in order. Each stage ends with a tangible deliverable and a review checkpoint, so mistakes are caught before they become the next tool’s input.
適合時可使用免費方案;開始前請確認供應商目前的使用限制與價格。 Compare the latest verified AI pricing before buying another subscription.
Suggested stack
Tools used in this workflow.
The process matters more than the brand. Use an approved equivalent when it offers the controls and output quality your organisation needs.
Inputs and ownership
Before you start
- 採用版本控制的程式碼庫、issue 與驗收標準
- 不含正式環境機密資訊的安全開發環境
- 一位了解受影響系統並有權審查的審查人員
Interactive workflow
Complete each stage in order.
Tick a stage only after its deliverable and review checkpoint are complete.
-
將需求轉化為驗收標準、受影響元件、限制條件與預期的復原方式。
Deliverable可審查的工程需求文件
Review checkpoint絕不可暴露憑證、客戶資料或正式環境設定。
-
要求 AI 助理先檢查相關程式碼並提出小範圍變更計畫,再開始產生程式碼。
Deliverable範圍明確的實作計畫
Review checkpoint逐行檢查所有變更與相依套件。
-
實作最小且完整一致的變更,只有在需要解釋不明顯的設計決策時才加入註解。
Deliverable聚焦的程式碼變更
Review checkpoint測試失敗路徑、權限與不可信任輸入。
-
依風險程度執行格式檢查、靜態分析、單元測試、整合測試、安全性檢查與迴歸測試。
Deliverable有紀錄的驗證結果
Review checkpoint拒絕夾帶在此次變更中的無關重構。
-
發布前完成人工程式碼審查、部署審查、監控與復原準備。
Deliverable經核准的發布與復原計畫
Review checkpoint依驗收標準監控部署後的實際行為。
Adapt, do not paste blindly
Working prompts for this recipe.
Replace bracketed placeholders, supply approved sources and remove unnecessary personal or confidential information.
工作提示詞
僅在替換每一個方括號 placeholder 並移除不必要的敏感資訊後使用。
審查下方程式碼任務與提供的 repository context。先重新說明驗收標準,找出受影響元件、安全邊界、測試與未知事項,再提出最小變更計畫。在列出缺少資訊前,不要撰寫程式碼。保留範圍外的既有行為,且絕不可要求或暴露機密資訊。 任務: [TASK] 背景: [APPROVED CODE CONTEXT]
最終審查提示詞
作為第二輪檢查清單使用,不代表已核准發布。
依照以下預期成果審查草稿:讓 AI 輔助的程式碼變更從明確需求開始,經過安全性與測試檢查,再由具明確責任的人員完成核准。列出缺乏依據的宣稱、缺少的證據、語意不明之處、隱私疑慮、無障礙問題,以及仍需要人工核准的行動。在分別列出這些問題前,不要改寫草稿。
Human review required
Verification and cautions
- 使用前請驗證姓名、數字、引述與來源宣稱。
- 除非所選服務與帳號已獲核准可處理,否則請移除機密或個人資訊。
- 必須指定一位明確負責最終決策與發布內容的人員。
Keep the outcome, change the method
Practical alternatives
Continue with context