SShortSingh.
Back to feed

A Practical Guide to Using Stacked Pull Requests for Cleaner Code Reviews

0
·1 views

Stacked pull requests (PRs) are a development technique where a chain of branches each targets the one below it rather than the main branch, allowing large changes to be reviewed in smaller, focused layers. The approach is designed to reduce reviewer cognitive load — for example, a 1,400-line change can be split into four PRs of roughly 350 lines each. Developers benefit by maintaining momentum, as they can continue building on upper layers while lower ones are still under review. However, the method is not universally applicable: small bug fixes, unrelated changes, or teams without an established stacked-PR workflow should avoid it. The GitHub CLI extension 'gh stack' supports the workflow with commands to initialize, view, and submit stacked PRs from a single repository.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Anthropic's Claude Sonnet 5.5 Outperforms Opus 5.5 on Key Coding Benchmark at Half the Price

Anthropic released Claude Sonnet 5.5 on September 28, priced at $2/$10 per million tokens — exactly half the cost of Opus 5.5. On Terminal-Bench 4.0, a benchmark measuring real-world agentic coding performance, Sonnet 5.5 scored 70.6% against Opus 5.5's 66.4%, marking a rare instance where a mid-tier model outperformed its flagship sibling. Across most other benchmarks, however, Opus 5.5 holds narrow leads, and the two models are nearly indistinguishable on knowledge-work evaluations. A critical caveat is that the benchmark comparisons used different effort levels — Sonnet 5.5 was tested at Max effort while Opus 5.5 ran at a lower Xhigh setting, meaning per-task costs can actually favour Opus for complex workloads. The release also coincided with OpenAI's GPT-6 Sol launching at the same price point, signalling that mid-tier model pricing has effectively become a commodity.

0
ProgrammingDEV Community ·

Selenium vs Cypress: Which Testing Tool Should Beginners Learn First in 2026?

Selenium and Cypress are the two most in-demand automation testing tools appearing in job listings, posing a common dilemma for students and freshers entering the field. Selenium is an open-source browser automation tool supporting multiple languages including Java, Python, and JavaScript, while Cypress is a JavaScript-only tool that runs tests directly inside the browser for faster feedback. A key difference is browser support: Selenium covers Chrome, Firefox, Edge, and Safari, whereas Cypress supports Chrome-family browsers and Firefox, with Safari's WebKit engine still experimental. According to the World Quality Report 2025-26 by Capgemini, Sogeti, and OpenText, around 89% of organizations are piloting or using generative AI in quality engineering, yet nearly half are still in the planning stage for test automation. Experts recommend beginners pick one tool, learn it thoroughly, and build the foundational skill of writing reliable automated tests, since understanding the underlying code remains essential even as AI-assisted coding grows.

0
ProgrammingDEV Community ·

How to Build a Secure SMS OTP Login System With Cooldowns and Attempt Limits

A technical guide outlines best practices for implementing passwordless phone login using SMS one-time passwords, recommending developers treat the process as a state machine rather than simple send-and-check handlers. The approach involves issuing a random six-digit code, storing only a hashed digest, expiring it quickly, and allowing only one verification attempt per code. Four separate controls must be tracked independently: OTP expiry, minimum cooldown between sends, a per-window send quota, and a failed-attempt counter. Crucially, requesting a new code should rotate the existing secret without resetting the failure budget, closing a loophole that could allow unlimited guessing. The guide suggests example defaults of a 10-minute OTP lifetime, 60-second cooldown, five sends per hour, and five failed attempts, while emphasizing these values should be tuned against real-world abuse scenarios.

0
ProgrammingDEV Community ·

Developer builds AI governance framework after rogue agent leaked passwords to GitHub

A developer suffered a major security breach in December 2025 when an AI agent called OpenClaw automatically pushed 37 passwords, 12 API keys, and an entire personal vault to a public GitHub repository in plaintext. The incident occurred because OpenClaw was designed to auto-sync files to GitHub without content scanning, human confirmation, or an audit trail. After spending 72 hours rotating compromised credentials, the developer audited major AI frameworks including LangGraph, CrewAI, and AutoGen, finding none addressed any of the OWASP Agentic Top 10 security risks. In response, the developer built MAREF, a self-described agent governance operating system designed to cover all ten risks, and is now using it to manage 139 agents. The incident highlights a broader gap between emerging AI regulations — including the EU AI Act, US NIST guidelines, and Singapore's agentic AI framework — and the practical tooling needed to enforce safe agent behavior.

A Practical Guide to Using Stacked Pull Requests for Cleaner Code Reviews · ShortSingh