Inspiration
I've stumbled across actual leaked API keys just browsing random repos on GitHub. That stuck with me. Nobody has time to manually review every pull request for hardcoded secrets or a sketchy SQL query, so stuff like that just sits there until something bad happens. I wanted to build something that catches it before that happens, and doesn't just point at the problem, actually hands you the fix.
What it does
Paste in a GitHub repo URL and Patch does the rest. It clones the repo, scans it for hardcoded secrets, injection bugs, and outdated packages, checks Tavily for any live CVEs tied to what it finds, and writes an actual patch for each issue. You get the exact file, the exact line, the exact code that tripped it, no digging required. And under the hood, the whole scan is running as a real Render Workflow.
How we built it
Detection happens in two passes. The first is plain regex, and it's deliberately boring: known key formats for AWS, GitHub, Stripe, that kind of thing, plus known bad code shapes like string-concatenated SQL or a raw eval call. Boring is good here, it means the results are deterministic. Run it on the same repo twice, get the same answer twice.
The second pass is where it gets more interesting. An AI model actually reads through the source, in whatever language it's written in, and picks up on things regex just can't catch, template injection, a request that's disabled TLS verification, stuff that only makes sense once you understand what the code is actually doing.
For the dependency side, Tavily is doing the heavy lifting. Once we've pulled a package name and version out of a manifest file, we fire a Tavily query scoped specifically to nvd.nist.gov and cve.org, nowhere else, so we're not pulling garbage off some random blog. It comes back with live results and we pull the real CVE IDs straight out of them. The whole point is that a model's knowledge stops at its training cutoff, but a CVE dropped yesterday still shows up because Tavily is actually searching the web right now, not remembering. We tested this against a real vulnerable dependency and it pulled back CVE-2026-25765, live, not a guess.
Patch generation runs through Qwen on Alibaba Cloud's Model Studio, writing a plain-English explanation plus an actual diff for each finding.
And then there's the Render side, which honestly ended up being one of my favorite parts to build. This isn't just "the backend happens to be deployed on Render." The scan itself runs as a Render Workflow, a real managed task, not a function stuffed inside a web request. Cloning, scanning, the Tavily lookup, and patch generation are each their own step in that task. Every run spins up on its own dedicated instance, has retries built in, and gets a 30 minute timeout so a slow AI call never just kills the whole thing. The backend kicks it off through Render's own REST API, and you can watch the logs stream in live on the Render dashboard while it runs, step by step. It's the exact same pipeline code as the regular in-app scan, just triggered a different way, one codebase, two ways to run it.
Challenges we ran into
The LLM connection gave me the most grief, honestly. Wrong base URL, wrong path, and it just sat there timing out in a way that looked like the model was slow when really the request was going nowhere. Took actual log-diving to catch. On top of that, I had to cap how much of a repo gets scanned, because a real, huge repo will happily hang the whole thing if you let it, and I had to be careful scoping Tavily's search so it only trusted the actual authoritative CVE sources instead of anything that came back.
Accomplishments that we're proud of
Getting real CVE data flowing live through Tavily instead of leaning on whatever the model happened to remember. Getting the Render Workflow to genuinely run the same pipeline as the normal scan, not a stripped-down copy, just on its own dedicated instance with real retry logic. And honestly, watching it catch things like SSTI and a disabled TLS check, stuff a regex-only scanner would just walk right past.
What we learned
Combining boring deterministic rules with an actual reasoning pass catches a lot more than either one alone would. Tavily changed how I think about "live" data entirely, there's a real difference between a model guessing based on old training data and something actually checking right now. And Render Workflows taught me a lot about not stuffing long AI jobs into a web request and just hoping they finish in time.
What's next for Patch
Reviewing individual PRs and commits instead of always scanning the whole repo. A GitHub Action so it just runs automatically on every pull request. And a security score that tracks whether a repo is actually getting safer over time as fixes land.
Log in or sign up for Devpost to join the conversation.