Skip to main content

Using Autofix in Code Reviews

Code Reviews Autofix, suggests code changes that fix some of the issues a Code Reviews scan finds.

Written by David Martin


What is Autofix?

Autofix fixes issues for a specific set of Code Reviews rules, so it can't fix every issue a scan flags. In a scan report, a green magic wand icon next to an issue means Autofix can fix it.
​

Autofix delivers its changes as an Autofix PR, which you can inspect in your Git provider before you merge. Each Autofix PR includes every issue Autofix can fix, whether or not you selected it. Dismiss any issues you want to keep before you create the Autofix PR.
​

How do I get an Autofix suggestion on Clayton.io?

You can get Autofix suggestions for issues in any branch that has a scan report. Issues that Autofix can fix have a green magic wand icon next to their name.

  1. Open your project in Code Reviews.

  2. Find an issue with a green magic wand icon next to its name.

  3. Click the issue to see every instance of it in your project.

  4. Dismiss any instances you don't want Autofix to change.

  5. Click Create Autofix PR.

Code Reviews then creates the Autofix PR, which can take a few minutes if there are many issues to fix. When it's ready, open the PR in your Git provider to check the changes before you merge.

How to create an Autofix PR


​How to create an Autofix PR in Gearset pipelines
If any of your PRs have issues that can be auto-fixed, there is an option to automatically create a fix PR.

Select the rule and then click on Create Autofix PR . You'll then see the summary of the rules and issues that will be fixed:

If everything looks good, you can go ahead to Create Autofix PR.

The Autofix PR will then be generated and you'll see an Autofix Bot icon in pipelines next to your original developer sandbox. You can click on it to check its details and Apply fixes:

Which rules does Autofix support?

The following table lists the Code Reviews rules that Autofix can fix, and the metadata type each rule checks.

Rule

What it fixes

Metadata type

Incorrect sharing clauses

Missing or incorrect sharing clause

Apex

Inefficient calls to Schema.getGlobalDescribe

Resource-intensive call to Schema.getGlobalDescribe

Apex

Insecure cookies

Insecure cookie

Apex

Missed opportunity: Null Coalescing Operator

Null check that can use the null coalescing operator

Apex

Missed opportunity: Safe Navigation Operator

Null check that can use the safe navigation operator

Apex

Missing annotation @IsTest in test methods

Test method without the @IsTest annotation

Apex

Update roleAndSubordinates to roleAndSubordinatesInternal

Use of roleAndSubordinates

Apex

Breaking change in LWC host access

Incorrect host component access

LWC

Breaking change in LWC import and export statements

Invalid import or export statement

LWC

Breaking change in LWC style access

Incorrect style access

LWC

Unexpected console.logs

Leftover console.log debug statements

Visualforce, Aura, and LWC

Autocompletion enabled on password fields

Password field with autocompletion turned on

Visualforce

Incorrect Agentforce settings

Incorrectly configured setting

Agentforce

Use of deprecated Agentforce secure actions

Deprecated secure action

Agentforce

Related articles

To use Autofix on pull requests in a Gearset pipeline, see How to use Code Reviews Autofix in Pipelines.
​

If you have any questions about Autofix, please send a message to our support team, who will be happy to help.

Did this answer your question?