# Production Reliability vs Static Analysis

Static analysis examines source code without executing it. It can catch coding errors, suspicious patterns, type problems, security issues, maintainability problems, and policy violations.

# What it does not know automatically

Static analysis does not automatically have the full operational context of production: how many services depend on a component, what traffic reaches it, whether the area has caused incidents, or how difficult rollback would be.

# Example

A small change in a shared authentication library may pass static analysis while still having a wide production reach. Dependency usage, production traffic, incident history, and testing coverage add context that is not contained in the diff alone.

# Use the layers together

Static analysis gives code evidence. Testing gives verification evidence. Production context gives impact evidence. Runtime signals give operational evidence. Incident history gives historical evidence.

# AI generated code

Static analysis can check generated code for known issues, code review can examine implementation, and production reliability analysis can examine what the generated change touches.  
Tomosu's **Production Reliability Index (PRI)** is designed to combine reliability signals around a change.  
Explore PRI: [https://tomosu.ai/start](https://tomosu.ai/start)
