> What evidence do we have that code review is good for spotting bugs?
There are papers that show positive results for Fagan inspection (1976 onwards) and I'd put good money on there being a straight line between IBM having good results with that method and more recent devs believing that code review is good for finding bugs, despite the loss of a formal structure.
> we think that code review is good for spotting bugs but what it's actually good for is knowledge sharing.
It can be both! I'm not sure it is, but there's nothing contradictory in that.
> Ask engineers why they review code, and most will say they do it to find bugs. In 2013, Alberto Bacchelli and Christian Bird studied code review at Microsoft and classified 570 review comments. 44% of developers ranked finding defects as their top reason for reviewing. Only 14% of the actual comments were about defects. Five years later, Caitlin Sadowski and her colleagues looked at nine million reviewed changes at Google and reached the same conclusion.
Proportion of comments tells you nothing about whether it's a good technique for finding bugs. It just tells you what the spread of comments is across the different purposes for which the channel is being used.