Skip to content

Product

FixPilot

The change that fixes it, with a test that proves it.

The problem

Knowing about a vulnerability is not the work. Writing the patch, not breaking anything, and getting it reviewed is the work — and it is the part that does not happen.

How it works

  • A patch scoped to the smallest change that fixes the finding. Not a refactor, not a version bump of everything, not a reformatted file.
  • A test that fails against the old code and passes against the new one. A proposed fix that cannot produce that test is never proposed.
  • It opens a pull request on a branch. Delivery is off until you turn it on, and nothing merges without a human.
  • Rejecting one with a reason changes what is proposed next.

What it does not do

It will not touch a finding it cannot write a failing test for, and it refuses rather than guessing. Some fixes are architectural, and for those it says so.