Key idea
Tests check what you thought of. The diff shows what actually changed, including what nobody thought of. Read every line before it's merged: once it ships, it's your code, whoever typed it.
Where to see it
- Before you commit:
git diffshows your uncommitted changes. - On a branch:
git diff mainshows everything the branch changes. - In a pull request: the Files changed tab on GitHub, one file at a time.
Lines starting with + were added, lines with - removed. The rest is context, so you can see where the change sits.
What to look for
Go through a diff with the same questions every time, in this order:
- Scope. Do the changed files match the brief? A diff to one endpoint that also edits config, CI or unrelated files needs an explanation.
- Dependencies. Did
package.jsonor the lockfile change? Look up every new package yourself before accepting it (lesson 4.1.2). - Input. Find everything that comes from a request: body, headers, query, URL. Is it checked? Where does it end up: a page, a database query, a file, a shell command?
- Who may do this. For every new or changed endpoint: does it check which user is asking, and whether they're allowed?
- Secrets. Any key, token or password typed into the code?
- Weakened checks. Deleted or skipped tests, loosened validation, errors caught and ignored. Agents sometimes make a failure go away instead of fixing it.
- The criteria. For each acceptance criterion, point to the lines that do it and the test that proves it.
If a part doesn't make sense, ask the agent to explain it. Then check the explanation against the code: an explanation is a claim too.
Undo at any stage
git restore server.js
Discards the uncommitted changes to one file; git restore . does the whole project.
git revert <commit>
Makes a new commit that undoes that one. History keeps both, so it's safe on a branch other people use. git log --oneline lists commits.
Open the merged pull request on GitHub and choose Revert. GitHub opens a new pull request that undoes it; review and merge it like any other.
A revert undoes code, not everything the code did. Anything it deleted, sent or charged while it was live stays done, which is why the reading happens before the merge.
Check yourself