Code Keep connects your GitHub repositories, indexes manifest declarations and active AST usage sites, detects actionable CVEs, and autonomously opens tested remediation pull requests. Humans retain merge control.
Every fix is synthesized and compiled inside disposable Docker sandboxes.
Short-lived GitHub App tokens expire after the run. Never stored in database.
Tree-sitter symbol graphs pinpoint exact call-sites before proposing breaking upgrades.
Autonomous bot never clicks merge. Developers hold final review authority.
Traditional tools create blind PRs that break production. Code Keep builds a durable index of every manifest, resolved lockfile, and active syntax node.
Know exactly where a library is called before changing versions. Tree-sitter parses JavaScript, TypeScript, and Python call sites to verify API deprecations and breaking method changes.
PRs are never opened on hunches. Remediation triggers only when CVE severity, target compatibility, and commit freshness satisfy standing policies.
Code Keep executes package upgrades and test suites in bounded, ephemeral containers (DockerSandboxRunner). Untrusted dependencies
cannot compromise host resources.
When a pull request opens, Code Keep dispatches a formatted markdown report directly to maintainers with execution timings, sandbox logs, and source diffs.
A transparent, deterministic pipeline. Every step produces durable database audit logs so developers know exactly how and why a change was synthesized.
OAuth identifies the human user, while a GitHub App installation provides scoped access to chosen repositories. Tokens are generated on-the-fly and expire in minutes.
Temporary shallow clone indexes package.json, requirements.txt, pyproject.toml, and lockfiles. Source code is scanned for real call sites.
The remediation agent modifies manifests, applies semantic code transformations to adapt to breaking APIs, and executes existing test suites inside an isolated container.
A pull request is pushed with exact evidence, test outputs, and CVE citations. An autonomous remediation report is emailed to the team. Code Keep stands down for human review.
Inspect the exact patches generated by Code Keep. Manifest upgrades paired with source-level AST rewrites.
--- a/package.json +++ b/package.json - "axios": "0.21.1", + "axios": "^1.7.4", "express": "^4.19.2", "typescript": "^5.4.0"
--- a/src/api/client.ts +++ b/src/api/client.ts - const res = await axios.get(url, { cancelToken: token.source }); + const controller = new AbortController(); + const res = await axios.get(url, { signal: controller.signal }); return res.data;
Everything you need to know about security boundaries, sandboxing, and repository permissions. Click any item to expand or collapse.
Join the waitlist to receive priority onboarding when our autonomous remediation sandbox launches.
No credit card required · Row-Level Security enforced · Zero auto-merge guarantee