← Back to the post

Distribution kit

Ship it everywhere.

Platform-native versions of The Capacity to Read — the main essay stays on the site; these are the repurposed pieces that point people to it.

Each card is ready to paste. Copy the post, copy the hashtags, mind the character counter, and link back to the canonical essay so the traffic comes home.

in

LinkedIn

Professional-leaning hook + takeaway. 1–3 short paragraphs perform best.

1513 / 3000

Code review rests on a quiet assumption: that a human can actually read what ships. I built an interactive piece to test that assumption. It doesn’t survive contact with the math.

Start with the one number that matters. The largest study of its kind — 2,500 reviews across 3.2M lines at Cisco (SmartBear) — found reviewers catch defects effectively at about 400 lines/hour, and detection collapses after ~60–90 minutes of reading. Give an engineer a generous 4 focused review-hours per sprint and you get a hard ceiling: ~1,600 lines they can truly review.

Now fill the tank. On a two-pizza team (6–8 people), coordination overhead alone pushes internal review most of the way to that line — before a single line of external code. Then add the part nobody talks about: 70–90% of a modern app is open-source code you pulled in, not wrote. ~900 dependencies in the average app. In some cases 95–97% of your codebase is someone else’s, and 71% of vulnerable components are transitive — dragged in by your dependencies’ dependencies.

Put dependency code against a 1,600-line budget and the meter doesn’t stretch. It snaps. Log4Shell was that arithmetic becoming visible overnight. XZ was caught by luck, not review.

The honest conclusion: at modern scale, the only reviewer that can read what actually ships is not a person. That’s not a process failure. It’s arithmetic — and it reframes what AI code review is actually for.

Playable version (slide the team size, flip on the dependency iceberg) in comments. 👇

#softwareengineering #codereview #opensource #appsec

Link back to: https://jasonburt.page/blog/code-review-capacity

M

Medium

Repost as "The Code Nobody Reads" (history: 2026-07-02_medium_general_code-nobody-reads). Import with a canonical link back; paste the full essay body beneath this block.

941 chars

Medium title: The Code Nobody Reads

Subtitle: Code review assumes a human can read what ships. Here’s the arithmetic that says they can’t.

Before you import: Use Medium’s “Import a story” tool with the canonical URL (jasonburt.page/blog/code-review-capacity) so Medium credits the original and you avoid duplicate-content penalties. Add this line under the title:

Originally published at jasonburt.page. This version is text-only — the interactive one (slide the team size, flip on the dependency iceberg, run the dependency scan) lives on the site.

Tags: Software Engineering · Code Review · Open Source · Security · Programming

Pull-quote to feature: “The meter doesn’t stretch. It snaps.”

Then paste the full essay body: open on the 400-LOC/hour ceiling, walk from the lone engineer to the two-pizza team, drop the 70–90% open-source iceberg, and close on Log4Shell / XZ and the reviewer that isn’t a person.

#Software Engineering #Code Review #Open Source #Security #Programming

Link back to: https://jasonburt.page/blog/code-review-capacity

🦋

Bluesky

Single skeet — keep it under 300 characters incl. the link.

224 / 300

A reviewer can truly read ~1,600 lines/sprint (400 LOC/hr, SmartBear). But 70–90% of your app is open-source you didn’t write — ~900 deps, 71% transitive. The math snaps. New interactive: watch code review run out of room 👇

#softwareengineering #codereview

Link back to: https://jasonburt.page/blog/code-review-capacity

𝕏

X / Twitter

Hook skeet of a thread. Keep the first post under 280.

240 / 280

Code review assumes a human can read what ships.

A reviewer catches defects at ~400 LOC/hr. Give them 4 hrs/sprint = ~1,600 lines.

Now: 70–90% of your app is open-source you never read. ~900 deps.

The budget doesn’t stretch. It snaps. 🧵

#softwareengineering #codereview

Link back to: https://jasonburt.page/blog/code-review-capacity