How it works
From disclosure to tested PR — on its own shift.
Every signal runs the same three-step track. The test suite is the gate. The on-call only gets paged for contested decisions, security-sensitive surfaces, license concerns, or failing builds.
- 01WatchesMonitors connected GitHub repositories and their dependency trees.
Public and private advisory feeds, package-registry disclosures, and upstream breaking changes.
- 02InvestigatesReads the signal. Picks forward fix, downgrade, or pin against your policy pack.
SemVer, peer usage, license posture, and security-sensitive surfaces — chosen locally before any code is touched.
- 03Patch, test, reviewOpens a reviewable PR, runs the project test suite, and waits for approval.
The build is the gate. Red keeps the PR open. License churn, public-API breakage, and security-sensitive surfaces remain with a human — merge execution is disabled today.