How it works

From disclosure to tested PR — on its own shift.

Every signal runs the same three-step track. The test suite is the gate. The on-call only gets paged for contested decisions, security-sensitive surfaces, license concerns, or failing builds.

  1. 01
    Watches
    Monitors connected GitHub repositories and their dependency trees.

    Public and private advisory feeds, package-registry disclosures, and upstream breaking changes.

  2. 02
    Investigates
    Reads the signal. Picks forward fix, downgrade, or pin against your policy pack.

    SemVer, peer usage, license posture, and security-sensitive surfaces — chosen locally before any code is touched.

  3. 03
    Patch, test, review
    Opens a reviewable PR, runs the project test suite, and waits for approval.

    The build is the gate. Red keeps the PR open. License churn, public-API breakage, and security-sensitive surfaces remain with a human — merge execution is disabled today.