FixPilot
The change that fixes it, with a test that proves it.
The problem
Knowing about a vulnerability is not the work. Writing the patch, not breaking anything, and getting it reviewed is the work — and it is the part that does not happen.
How it works
- A patch scoped to the smallest change that fixes the finding. Not a refactor, not a version bump of everything, not a reformatted file.
- A test that fails against the old code and passes against the new one. A proposed fix that cannot produce that test is never proposed.
- It opens a pull request on a branch. Delivery is off until you turn it on, and nothing merges without a human.
- Rejecting one with a reason changes what is proposed next.
What it does not do
It will not touch a finding it cannot write a failing test for, and it refuses rather than guessing. Some fixes are architectural, and for those it says so.