PatchPilot
Watch Commander · supply-chain security

The model plans the fix.A signed, human-approved pipeline applies it.

PatchPilot finds the CVEs that actually reach your code, lets OpenAI Codex write the fix in a sandbox, signs the result, and waits for a tap on your phone. Every integration runs live (Codex, OSV, GitHub, Telegram) with a full audit trail behind each change.

Scan your own project
$npx patchpilot-cli scan
No auto-merge, no auto-deploy Signed provenance on every fix

Nine steps from a CVE to a signed, approved fix.

01Inventory
02Scan
03Reachability
04Risk
05Codex writes
06Validate
07Attest
08Approve
09Audit

Highlighted steps are PatchPilot's edge: reachability triage, Codex-written fixes, and a signed attestation, all gated behind a human tap.

Triage what's reachable. Fix it safely. Prove it with a signature.

Reachability / VEX-lite

Is the vulnerable package actually imported in your source? If not, it's de-prioritized. The CVE wall shrinks to the handful that matter.

Connect any model

Codex (GPT-5.5) is the only model that writes to the repo. Behind it, configured cloud or local providers by policy, then a deterministic fallback. Secrets never reach the cloud.

Signed attestation

Every fix ships a verifiable HMAC statement of from→to, validation result, and files changed, embedded in the pull request.

Human-in-the-loop

Inline Telegram buttons to approve, reject, retry safer, or rollback. No auto-merge, no auto-deploy, no exceptions.

OpenAI Codex · GPT-5.5Ollama · localOpenRouter · any modelOSV + OSV-ScannerGitleaksTrivySyft · SBOMEPSSCISA KEVMCP serverTelegram · HMACPostgres 16Redis · BullMQNext.js 16TypeScript

Your repos and your AI agents.
One command center.