--- id: P-REINFORCE-AUTO-WIKI-AUTO-001 category: "10_Wiki/πŸ’‘ Topics/Automation" confidence_score: 0.95 tags: [automation, code-review, static-analysis, linting, quality-gate, dev-tools, p-reinforce] last_reinforced: 2026-05-01 --- # [[Automated Quality & Review|Automated Quality & Review]] ## πŸ“Œ ν•œ 쀄 톡찰 (The Karpathy Summary) > "인간 리뷰어보닀 λ¨Όμ € μ½”λ“œμ˜ ꡬ문, μŠ€νƒ€μΌ, μ•Œλ €μ§„ 취약점을 ν•„ν„°λ§ν•˜μ—¬ ν’ˆμ§ˆμ˜ μ΅œμ†Œ 기쀀을 κ°•μ œν•˜κ³ , 리뷰 μ‹œκ°„μ„ κ³ λΆ€κ°€κ°€μΉ˜ 섀계 토둠에 μ§‘μ€‘μ‹œν‚€λŠ” μ§€λŠ₯ν˜• μžλ™ν™” λ°©μ–΄μ„ ." ## πŸ“– κ΅¬μ‘°ν™”λœ 지식 (Synthesized Content) μžλ™ν™”λœ ν’ˆμ§ˆ κ΄€λ¦¬λŠ” ν˜„λŒ€ μ—”μ§€λ‹ˆμ–΄λ§μ˜ 생산성을 κ²°μ •μ§“λŠ” ν•„μˆ˜ μΈν”„λΌμž…λ‹ˆλ‹€. 1. **정적 뢄석 및 λ¦°νŒ… (Static Analysis & Linting)**: * **ꡬ문 및 μŠ€νƒ€μΌ κ°•μ œ**: λ¦°ν„°(Linter)와 포맀터(Formatter)λ₯Ό 톡해 νŒ€μ˜ μ»¨λ²€μ…˜μ„ μžλ™μœΌλ‘œ μœ μ§€ν•˜λ©° μ†Œλͺ¨μ μΈ μŠ€νƒ€μΌ λ…ΌμŸμ„ μ œκ±°ν•©λ‹ˆλ‹€. * **[[SAST (Static Application Security Testing)|SAST (Static Application Security Testing]]**: μ†ŒμŠ€ μ½”λ“œ λ ˆλ²¨μ—μ„œ OWASP Top 10 λ“±μ˜ λ³΄μ•ˆ 결함을 쑰기에 νƒμ§€ν•©λ‹ˆλ‹€. 2. **리뷰 μžλ™ν™” (Review Automation)**: * **ν’ˆμ§ˆ 게이트 (Quality Gate)**: CI/CD νŒŒμ΄ν”„λΌμΈκ³Ό μ—°λ™ν•˜μ—¬ ν…ŒμŠ€νŠΈ 컀버리지, μ½”λ“œ λ³΅μž‘λ„, λ³΄μ•ˆ 기쀀을 μΆ©μ‘±ν•˜μ§€ λͺ»ν•œ PR의 병합을 μ‹œμŠ€ν…œμ μœΌλ‘œ μ°¨λ‹¨ν•©λ‹ˆλ‹€. * **사전 컀밋 ν›… (Pre-commit Hooks)**: μ½”λ“œκ°€ 원격 μ €μž₯μ†Œμ— ν‘Έμ‹œλ˜κΈ° μ „ λ‘œμ»¬μ—μ„œ 즉각적인 ν”Όλ“œλ°±μ„ μ œκ³΅ν•˜μ—¬ μˆ˜μ • μ£ΌκΈ°λ₯Ό λ‹¨μΆ•ν•©λ‹ˆλ‹€. 3. **도ꡬ 톡합 (Tools Integration)**: * GitHub Actions, SonarQube, CodeClimate λ“± λ‹€μ–‘ν•œ 뢄석 도ꡬλ₯Ό PR μ›Œν¬ν”Œλ‘œμš°μ— ν†΅ν•©ν•˜μ—¬ μ½”λ“œ 건강 μƒνƒœλ₯Ό κ°€μ‹œν™”ν•˜κ³  μΆ”μ ν•©λ‹ˆλ‹€. ## ⚠️ λͺ¨μˆœ 및 μ—…λ°μ΄νŠΈ (Contradictions & RL Update) - **μ˜€νƒ(False Positive)의 λ…Έμ΄μ¦ˆ**: μžλ™ν™” 도ꡬ가 μ‹€μ œ μœ„ν˜‘μ΄ μ•„λ‹Œ μ½”λ“œλ₯Ό κ²°ν•¨μœΌλ‘œ 지적할 경우 개발자의 ν”Όλ‘œλ„κ°€ μ¦κ°€ν•©λ‹ˆλ‹€. ν”„λ‘œμ νŠΈ λ§₯락에 λ§žλŠ” κ·œμΉ™ μ»€μŠ€ν„°λ§ˆμ΄μ§•κ³Ό μ˜ˆμ™Έ 처리 정책이 μ€‘μš”ν•©λ‹ˆλ‹€. - **μΈκ°„μ˜ λŒ€μ²΄ λΆˆκ°€λŠ₯μ„±**: μžλ™ν™”λŠ” μ •ν•΄μ§„ νŒ¨ν„΄μ€ 잘 μ°Ύμ§€λ§Œ λΉ„μ¦ˆλ‹ˆμŠ€ λ§₯락, μ•„ν‚€ν…μ²˜ μ˜λ„, λ³΅μž‘ν•œ μ ‘κ·Ό μ œμ–΄ λ‘œμ§μ€ μ΄ν•΄ν•˜μ§€ λͺ»ν•©λ‹ˆλ‹€. κΈ°κ³„λŠ” 'κ·œμΉ™ μ€€μˆ˜'λ₯Ό, 인간은 'μ˜λ„μ™€ 섀계'λ₯Ό κ²€μ¦ν•˜λŠ” λΆ„μ—… ꡬ쑰λ₯Ό μœ μ§€ν•΄μ•Ό ν•©λ‹ˆλ‹€. ## πŸ”— 지식 μ—°κ²° (Graph) - [[SAST (Static Application Security Testing)|SAST (Static Application Security Testing]]: 정적 λ³΄μ•ˆ λΆ„μ„μ˜ 심화. - [[CI-CD Pipeline|CI-CD Pipeline]]: μžλ™ν™” 검증이 μ‹€ν–‰λ˜λŠ” 핡심 ν™˜κ²½. - [[Code Review Checklist|Code Review Checklist]]: μžλ™ν™”κ°€ μ²˜λ¦¬ν•˜μ§€ λͺ»ν•˜λŠ” μΈκ°„μ˜ μ˜μ—­. - Shift-Left Security: λ³΄μ•ˆ 점검을 μžλ™ν™”λ‘œ μ‘°κΈ° λ„μž…ν•˜λŠ” μ „λž΅. - [[Technical-Debt|Technical Debt]]: μžλ™ν™”λœ λŒ€μ‹œλ³΄λ“œλ₯Ό 톡해 κ΄€λ¦¬λ˜λŠ” 뢀채. ---