Skip to content
Notifications
Clear all

Which AI code reviewer has the best precision on C++ PRs?

24 Posts
24 Users
0 Reactions
58 Views
(@contrarian_kevin)
Honorable Member
Joined: 3 months ago
Posts: 418
 

SonarCloud's PR decoration is slick, but their rule sets are a black box. You're trusting a vendor to define "learning" for you, and their priorities shift. Last year they pushed a whole batch of "maintainability" rules that flagged trivial formatting as critical issues.

Good for that initial "aha" on a typo. Then you're stuck tuning out their marketing-driven noise.


Just saying.


   
ReplyQuote
(@danielj)
Reputable Member
Joined: 3 months ago
Posts: 254
 

SonarCloud's clear, direct feedback is indeed great for catching those early mistakes. The PR decoration makes it impossible to miss.

My only gripe with their learning focus is that the rule explanations sometimes stop short. They'll tell you *what* is wrong with the stream operator typo, but rarely dig into *why* that pattern is a common slip-up or how to avoid it next time. The "learning" feels a bit surface-level compared to truly understanding the underlying concept.


spreadsheet ninja


   
ReplyQuote
(@grafana_guy_night)
Honorable Member
Joined: 6 months ago
Posts: 427
 

Hey, as someone also new to C++ and Grafana, I get the need for clear feedback. I tried a few AI reviewers and was surprised how many missed that stream operator typo. They'd fixate on the pointer and ignore the `std::cout <`. SonarCloud caught it for me, but it still felt like luck.

Have you tried running just a strict Clang-Tidy check first? It's not "AI" but it's precise on core language stuff like that, and it uses your exact compiler. Might be a good baseline before adding fancier tools.



   
ReplyQuote
(@chrisp)
Honorable Member
Joined: 3 months ago
Posts: 462
 

That's a solid test snippet, and it nails the kind of thing you need to catch early. For that specific example, I've seen both SonarCloud and CodeQL correctly flag the stream operator typo and the missing arrow operator.

But for a newcomer, the big difference is in the feedback. SonarCloud will give you a direct, inline message about the invalid operator. CodeQL might show a data flow path proving `data` could be null, which is great for learning pointer safety, but it might not comment on the typo at all. It depends on the active query suite.

My two cents? Start with the compiler's own tools. A strict Clang-Tidy run in your CI, as user341 mentioned, will catch those core syntax and safety issues with near-zero false positives because it uses your exact build. It's not as flashy, but it gives you a clean baseline. Then you can layer on an AI reviewer for higher-level logic checks once you're more comfortable.


✌️


   
ReplyQuote
(@emilyf)
Reputable Member
Joined: 3 months ago
Posts: 227
 

Great example. I'm also new to C++ and tried a few AI reviewers. The typo with `std::cout <` is exactly the kind of simple mistake I need caught, but I found many tools focused on the more complex null check and missed it. That was frustrating.

SonarCloud did flag it when I tried. But I'm curious, does anyone know if their precision drops off for more subtle C++ patterns? I'm thinking about template code or move semantics, where the environment issues people mentioned could really matter.



   
ReplyQuote
(@danielr23)
Reputable Member
Joined: 3 months ago
Posts: 359
 

Forget AI for this. You need a static analyzer that understands your exact build.

Run `clang-tidy` with your existing CMake/Make setup first. It'll catch the stream typo and pointer issue because it parses the same AST as your compiler. Zero environment mismatch.

Then, if you still want a second pass, CodeQL has the best precision on data flow like your `getDataPointer()` example. But you must replicate your dependency graph in its build step, which is a significant CI cost.

Precision comes from analyzing the code you actually ship, not a guess. Start with the toolchain you already pay for.


Trust, but verify


   
ReplyQuote
(@bluefox)
Reputable Member
Joined: 3 months ago
Posts: 228
 

Totally get the need for clear, correct feedback when you're new to a language. For that example, I'd actually skip the "AI" reviewers and go straight to the compiler's own tools.

A simple `-Werror -Wall` in your build and maybe a basic `clang-tidy` run will nail the stream operator typo and the pointer issue with zero guesswork. It sees exactly what your compiler sees. That gives you a quiet, precise baseline.

Then you can layer on something like SonarCloud for the learning hints, knowing the foundational stuff is already caught.



   
ReplyQuote
(@elliotv)
Reputable Member
Joined: 3 months ago
Posts: 380
 

I completely agree with this layered approach. Starting with the compiler's own diagnostics and `clang-tidy` provides a deterministic foundation, which is crucial.

One practical caveat to the "zero guesswork" promise is that `clang-tidy` checks aren't universally enabled by default. For maximum precision on that example, you'd need to explicitly enable checks like `readability-container-size-empty` and `clang-analyzer-core.NullDereference`. Without a tailored configuration, you might miss the null check warning, even though you'd still catch the `-Wall` violations.

So the workflow becomes: first, enforce `-Werror -Wall`. Second, define a project-specific `.clang-tidy` file that codifies your precision rules. This creates the quiet baseline. Only then does it make sense to add a secondary opinion from an external tool, and you can evaluate its value based on what, if anything, it adds beyond your now-strict local analysis.


null


   
ReplyQuote
(@davidm)
Reputable Member
Joined: 3 months ago
Posts: 270
 

That's a really good point about the .clang-tidy configuration. I'm just starting with it and didn't realize I was missing checks by using the defaults. I figured if I ran it, I'd get everything.

So the "zero guesswork" promise is only true if you do the work of setting up the config file first. That's a super helpful caveat, thanks for pointing it out. I'll be sure to define one for my project.



   
ReplyQuote
Page 2 / 2