World Congress 2025 Aug 20, 2025 Session details

How we built an AI-powered code reviewer in 80 hours

Yan Cui

Integrating AI is only 10% of building a production-ready code reviewer. Discover how defensive AWS serverless architecture actually tames context limits, rate caps, and expensive hallucinations.

Pause
Mute Enter Fullscreen
#1 about 3 min

Overview of the AI-powered serverless code reviewer

A demonstration of how the tool scans pull requests to identify security risks and anti-patterns.

#2 about 3 min

High-level architecture for serverless event processing

How GitHub webhooks, EventBridge, Lambda, and AppSync coordinate to handle pull request analysis.

#3 about 5 min

Securing customer source code with Amazon Bedrock

Why privacy guarantees and serverless token-based pricing drove the choice of Bedrock over direct model APIs.

#4 about 3 min

Managing timeouts and limits with async invocations

How handling large pull requests requires durable retries and strict concurrency limits to avoid Lambda timeouts.

#5 about 3 min

Context window limitations in large language models

Why large context windows excel at recall but fail at complex reasoning beyond limited token counts.

#6 about 3 min

Working around API rate limits and model outages

Strategies for maximizing throughput using cross-region inference and managing reliability via fallback provider APIs.

#7 about 3 min

Controlling the high infrastructural costs of AI code analysis

How exclusively scanning changed code lines enables a financially sustainable model for customer AI usage.

#8 about 4 min

Implementing durable execution with local checkpoints

Using a DynamoDB-based idempotency pattern instead of Step Functions while running static analysis parallel to LLM calls.

#9 about 5 min

Handling hallucinations in formatted JSON and code structures

Why LLMs generate imaginary line numbers or outdated fixes and how retrieval constraints impact reliability.

Matching moments

1:55 min

Shifting developer workloads and realistic AI productivity gains

Chris Heilmann +2 · LIVE

6:53 min

Reviewing recent technology and AI tool headlines

Chris Heilmann +1 · LIVE

1:56 min

Analyzing cloud-based AI code completion architectures

Daniel Savenkov Daniel Savenkov · World Congress 2024

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

1:58 min

Managing overwhelming artificial intelligence pull requests in open source

Chris Heilmann +2 · LIVE

4:11 min

Filtering AI code generations and automating pull request reviews

Kevin Lewis Kevin Lewis · World Congress 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 14:50–15:20

Tech Leaders Stage

Keeping Code Quality at AI Speed

Daksh Gupta, Arthur Hicken, Jack Danger

Daksh Gupta
Arthur Hicken
Jack Danger
Open session

World Congress 2026 North America

September 24, 2026 · 16:10–16:40

Stage 2

The Death of the Code Review

Laurie Voss

Head of Developer Relations

Laurie Voss
Open session

World Congress 2026 North America

September 24, 2026 · 15:30–16:00

Stage 5

The reviewer can't be the author: independent verification for AI-generated code

Manish Kapur

VP, Product and Solutions at Sonar

Manish Kapur
Open session

World Congress 2026 North America

September 24, 2026 · 16:50–17:20

Mainstage

Building AI Products vs. Building With AI

Aparna Dhinakaran, Rukmini Reddy, Tamar Bercovici

Aparna Dhinakaran
Rukmini Reddy
Tamar Bercovici
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Mainstage

Running AI-Written Software in Production

Anurag Goel, Milin Desai

Anurag Goel
Milin Desai
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Stage 5

21 Experiments in Six Weeks: A Playbook for Improving Your AI Agent

Sofia Rest

Software Engineer at Sentry

Sofia Rest