codekeep
Autonomous Remediation Engine Early Access Waitlist

Dependency updates without the breaking change anxiety.

Code Keep connects your GitHub repositories, indexes manifest declarations and active AST usage sites, detects actionable CVEs, and autonomously opens tested remediation pull requests. Humans retain merge control.

Inspect Pipeline
Isolated Docker Sandboxes
Short-Lived GitHub App Tokens
Zero Auto-Merge Policy
codekeep-worker / runner-04
14:02:18 $ codekeep-agent scan acme-org/platform-core
14:02:19 [DISCOVERY] 4 projects found (2 Node, 2 Python)
14:02:21 [AST-INDEX] 312 packages · 48 active symbol sites
14:02:22 [EVALUATE] Target identified: axios 0.21.1 → 1.7.4
14:02:23 [SECURITY] Resolves CVE-2023-45857 (High Severity)
14:02:24 [SANDBOX] Spawning isolated container runner...
14:02:26 [VERIFY] Manifest bumped · AST patched · Tests passed (38/38)
14:02:28 [PR-OPENED] Branch: code-keep/deps/axios-1.7.4
14:02:29 [EMAIL-SENT] Remediation brief delivered to maintainers
14:02:30
100%
Isolated Execution

Every fix is synthesized and compiled inside disposable Docker sandboxes.

0 ms
Production Token Leakage

Short-lived GitHub App tokens expire after the run. Never stored in database.

AST-Level
Precision Analysis

Tree-sitter symbol graphs pinpoint exact call-sites before proposing breaking upgrades.

Strict Human
Merge Control

Autonomous bot never clicks merge. Developers hold final review authority.

Architectural Capabilities

Engineered for monorepos, hardened for production.

Traditional tools create blind PRs that break production. Code Keep builds a durable index of every manifest, resolved lockfile, and active syntax node.

Syntax-Tree (AST) Usage Verification

Know exactly where a library is called before changing versions. Tree-sitter parses JavaScript, TypeScript, and Python call sites to verify API deprecations and breaking method changes.

packages/auth/src/client.ts:42 axios.create({ baseURL }) Compatible
services/billing/sync.py:118 stripe.Charge.create() Deprecated API
apps/web/src/utils/sanitize.js:14 lodash.template() CVE-2021-23337

Deterministic Policy Gate

PRs are never opened on hunches. Remediation triggers only when CVE severity, target compatibility, and commit freshness satisfy standing policies.

Vulnerability Evidence VERIFIED
Sandbox Build Check PASSED
Auto-Merge Allowed DISABLED

Containerized Sandbox Runner

Code Keep executes package upgrades and test suites in bounded, ephemeral containers (DockerSandboxRunner). Untrusted dependencies cannot compromise host resources.

1. Bump
package / lock
2. AST Refactor
Source call-sites
3. Test Run
pytest / vitest
4. PR Dispatch
Branch + Report

Immediate Maintainer Briefing

When a pull request opens, Code Keep dispatches a formatted markdown report directly to maintainers with execution timings, sandbox logs, and source diffs.

TO: maintainers@acme-org.internal
[Code Keep] Automated Remediation for CVE-2023-45857 (PR #142)
Status: 38/38 tests passing · Duration: 4.8s · Sandbox clean
Execution Lifecycle

From detection to pull request in seconds.

A transparent, deterministic pipeline. Every step produces durable database audit logs so developers know exactly how and why a change was synthesized.

01 REPOSITORY AUTHORIZATION

Connect via GitHub App Installation

OAuth identifies the human user, while a GitHub App installation provides scoped access to chosen repositories. Tokens are generated on-the-fly and expire in minutes.

POST /api/github/installations/claim → user_id & repo isolation verified
02 SHALLOW CLONE & AST DISCOVERY

Multi-Manifest & Symbol Extraction

Temporary shallow clone indexes package.json, requirements.txt, pyproject.toml, and lockfiles. Source code is scanned for real call sites.

Tree-sitter AST Graph: 42 modules · 284 dependencies cataloged
03 ISOLATED CONTAINER REMEDIATION

Deterministic AST Refactoring & Verification

The remediation agent modifies manifests, applies semantic code transformations to adapt to breaking APIs, and executes existing test suites inside an isolated container.

DockerSandboxRunner: vitest run → 42 passed, 0 failed [OK]
04 PULL REQUEST & AUDIT REPORT

Branch Creation & Maintainer Handoff

A pull request is pushed with exact evidence, test outputs, and CVE citations. An autonomous remediation report is emailed to the team. Code Keep stands down for human review.

git push origin code-keep/deps/axios-1.7.4 → PR #142 opened
Audit Artifact Preview

Clear, verifiable diffs with zero hallucinations.

Inspect the exact patches generated by Code Keep. Manifest upgrades paired with source-level AST rewrites.

Remediation Succeeded code-keep/deps/axios-1.7.4
DockerSandboxRunner • 3.4s
Manifest Patch
--- a/package.json
+++ b/package.json
-    "axios": "0.21.1",
+    "axios": "^1.7.4",
     "express": "^4.19.2",
     "typescript": "^5.4.0"
AST Source Code Adaptation
--- a/src/api/client.ts
+++ b/src/api/client.ts
-  const res = await axios.get(url, { cancelToken: token.source });
+  const controller = new AbortController();
+  const res = await axios.get(url, { signal: controller.signal });
   return res.data;
Common Inquiries

Frequently asked questions.

Everything you need to know about security boundaries, sandboxing, and repository permissions. Click any item to expand or collapse.

No. Code Keep enforces a strict zero-auto-merge policy. The system discovers dependencies, resolves vulnerabilities, compiles source transformations, and verifies test suites, but the final pull request merge is strictly preserved under human control.
Repository access is granted via a GitHub App installation, distinct from user authentication. When a background scan or remediation runs, Code Keep generates a scoped, temporary installation token valid only for minutes. Installation tokens are never persisted in the database.
Code Keep currently supports Node.js (package.json, package-lock.json, npm, Bun) and Python (requirements.txt, pyproject.toml, uv.lock, pip, uv). Monorepo project discovery automatically detects nested workspaces.
Unlike tools that simply increment version strings, Code Keep parses your codebase using Tree-sitter. It identifies which functions and symbols you actually import from a dependency, cross-references breaking change changelogs, and rewrites modified signatures before running your local test suite.
Request Early Access

Upgrade dependencies with total confidence.

Join the waitlist to receive priority onboarding when our autonomous remediation sandbox launches.

No credit card required · Row-Level Security enforced · Zero auto-merge guarantee