This Solution doesn’t have a README yet.
Triages dependency vulnerabilities, infrastructure log anomalies, and security-relevant pull requests. It fixes small obvious issues with PRs and files durable GitHub issues when findings need human attention.
Query OSV.dev for known vulnerabilities by package name, version, and ecosystem
Query GitHub Advisory Database for vulnerabilities affecting a package
Parse a project's lockfile and check every dependency against OSV
Read a file from a GitHub repository
Create a new branch in a GitHub repository from a base ref
Create or update a file on a branch via the GitHub API
Open a pull request from a branch
File a GitHub issue for a security finding that needs human attention
Query Google Cloud Logging for security-related events
Scan all monitored repos for vulnerable dependencies and triage
Scan GCP logs for security anomalies
Triggered by GitHub PR webhooks; flag security concerns on opened/updated PRs