Nightly triage for vulnerable dependencies

The shift that patches your deps while you sleep.

Nightly triage, CI-validated fix PRs, and a Monday digest your CTO will actually read. Bracework watches your npm, pip, and Cargo lockfiles, drafts the smallest fix that closes each advisory, and only opens a pull request when the branch is already green on CI.

GitHub App install
npm · pip · Cargo
No scanner replacement
bracework / nightly-run
02:14 UTC · job #4,182
02:14:02ingest 14 advisories from OSV · npm + pip + cargo
02:14:09score 12 reachability-confirmed · 2 escalated
02:14:21draft patch: lodash 4.17.20 → 4.17.21 (prototype-pollution)
02:14:24draft patch: pyjwt 1.7.1 → 2.8.0 (key-confusion)
02:17:48ci green · services/api (312 tests) · services/web (1,048 tests)
02:17:51opened PR #2214 · auto-merge enabled · 1 reviewer
02:18:02major bump escalates: webpack 5.88 → 5.97 (awaiting human)
02:18:04digest queued · ships 07:30 local to 4 inboxes

Sample output from a real nightly run. No fictional dashboards — just the log lines that drive the work.

The incumbents underserve three places

Push-based bots are why your reviewers stopped reading the PR list.

Platform teams already pay for an SCA platform that talks about reachability and ownership graphs. The PRs still pile up. The dashboards still go unread. What is missing is a scheduler-driven, CI-validated, and calmly-summarized closing of the loop.

Nightly

A queue, not a push

Findings batch overnight. Reviewers see one item per night, not eighty per hour.

Pre-PR CI

Green before review

Every patch runs through your CI on a branch. If it fails, you never see the PR.

Email

A digest you actually read

Monday morning summary for engineers, security owners, and compliance — in plain English.

The nightly pipeline

Six steps. One human gets a single email Monday morning.

Bracework runs once per night per repo. It does not poll. It does not race. It produces the smallest change that closes the advisory, validates it, then files it.

  1. 01
    Ingest

    Pull advisories

    OSV, GHSA, vendor feeds. De-duped across your npm, pip, and Cargo lockfiles.

  2. 02
    Score

    Reachability + exploit

    Filter out advisories that could not reach your code, even if the dep is present.

  3. 03
    Draft

    Smallest fix

    A version bump, a codemod, or a vendor advisory pin. Never a drive-by refactor.

  4. 04
    Validate

    Run your CI

    The branch must be green. If CI fails, the PR is not opened — we try the next candidate.

  5. 05
    Open

    Single PR per night

    Auto-merge where allowed. One reviewer. Notes link the advisory and the CI run.

  6. 06
    Digest

    Monday digest

    A short email for engineers, security, and compliance. Escalations at the top.

How we differ

We sit on top of your scanner, not against it.

vs Dependabot / Renovate

Push → review, every hour

Bracework: Nightly batch → green branch, one PR

vs Snyk / Socket / Endor Labs

Find. Dashboards. Remind.

Bracework: Find + ship. Audit trail. Plain English.

vs AI fixer agents

Auto-commit, hope CI canary catches it

Bracework: Branch first, validate, then open PR

Bracework is not trying to replace your scanner. It is the calm remediation layer that turns its output into merged pull requests and a Monday summary your CTO will read on the train.

What ships Monday

One email. Four inboxes. No dashboard.

A weekly plaintext digest turns the reconciled PRs into a short note your CTO, security owner, and compliance lead can each read in under sixty seconds — with the PRs, advisories, and CI status linked in the same email.

  • Per-repo section with the week’s merged fixes and open PRs.
  • Each entry links the PR, the advisory, and the CI run that validated it.
  • Escalations are called out at the top in a single sentence — never buried.
  • Plain English, one paragraph; no metrics invented for the sake of dashboard.
Bracework — Week 47 digest
Mon · 07:30 local

Heads up: one breaking change escalated for a human call (lines 28–34). Everything else is ready to merge.

services/apimerged

Prototype pollution in lodash via transitive path

4.17.20 → 4.17.21 · PR #2214 · CI 312 tests

services/apimerged

Key-confusion in PyJWT (CVE-2024-53861)

1.7.1 → 2.8.0 · PR #2215 · CI 312 tests

services/webawaiting

RUSTSEC-2024-0439 — yanked crate `paste`

awaiting sponsor review · PR #2216

infra/cliescalated

Webpack 5.88 → 5.97 (major bump, 14 transitive changes)

needs human judgement — opened Monday only for you

Questions a platform lead would ask

The skeptical-reader FAQ.

If something on this list is on your mind, write to us at bracework-2@polsia.app.

Pilot intake

Give us one repo. We’ll hand you a Monday digest by week two.

The pilot installs the GitHub App on a single repo, runs for one week, and delivers a sample digest so you can see the format before you commit to a wider rollout.

Request a pilot

We reply from bracework-2@polsia.app within one business day.

Bracework is a remediation layer, not a scanner. Bring your own Snyk, Socket, or Endor Labs.bracework-2@polsia.app