DEV Community

Riven Desk
Riven Desk

Posted on

The AI PR that only touched .env.example (and quietly changed a default)

I almost rubber-stamped an agent PR last month because the title was "docs: sync .env.example with current config."

Diff looked tiny. A few comments. One new line in .env.example. CI green. No app code touched.

I almost hit merge. Then I checked what that "example" line actually did.

The agent had changed the documented default for a feature flag from false to true. In our setup, people copy .env.example into local and staging. One teammate already had. Overnight their environment started behaving like prod for a path that still had incomplete auth checks.

The PR description said "no behavior change." Technically true for the running servers that already had the old env. Practically false for every new clone and every fresh staging box.

My 60-second check for "docs only" / .env* / config PRs now:

  1. Diff the default values, not just the comments. What changed from false → true, empty → something, off → on?
  2. Ask: who copies this file, and when does that value become live?
  3. If the answer is "new environments," treat it like a behavior change even when no .ts / .py file moved.

If you want the fuller stop list I use before I trust an AI-written PR, the free one-pager is here: https://chopragunji.gumroad.com/l/zpnmdn

And if you have a scary AI PR sitting in review and want a second set of eyes, I'm doing a few $49 founding audits (normally $99): https://chopragunji.gumroad.com/l/byoyi/FOUNDING

Curious: has an "example config" or docs-only PR ever bitten you?

Top comments (0)