Inspiration Modern software supply chains rely heavily on third-party dependencies. Manually tracking CVEs, determining compatible SemVer upgrades, and ensuring zero regressions creates a massive operational bottleneck for engineering teams. We built PatchPilot to transform reactive security into an autonomous, self-healing DevSecOps pipeline that fixes software vulnerabilities with zero human intervention.
What it does PatchPilot is an autonomous multi-agent fleet powered by Gemini 3.5 Flash and the Google Antigravity SDK, designed to monitor, remediate, validate, and stream execution state in real time:
Scout Agent: Scans project manifest files (requirements.txt) against the OSV.dev database to instantly detect real-time CVE and GHSA advisories.
Fixer Agent: Leverages Gemini 3.5 Flash for deep SemVer compatibility reasoning and API contract analysis to formulate optimal non-breaking patch proposals.
Validator Agent: Installs proposed patches in an isolated sandbox and executes pytest. If a regression is detected, it triggers an atomic rollback and initiates a closed-loop recovery with Gemini to self-heal the build.
Cloud Telemetry: Enterprise-ready logging engine streaming every decision trajectory and agent reasoning live to Google Cloud Firestore.
How we built it Multi-Agent Orchestration: Built using Python and the Google Antigravity SDK (google-antigravity) along with Google GenAI SDK (google-genai).
AI Engine: Powered by Google Gemini 3.5 Flash for intelligent version path reasoning and self-healing analysis.
Vulnerability Intelligence: Direct integration with the OSV.dev REST API for real-time CVE/GHSA lookup.
Sandbox & Validation: Isolated environment running automated pytest suites to guarantee contract stability before patch confirmation.
Google Cloud Infrastructure: Integrated Google Cloud Firestore (Database: (default), Collection: patchpilot_telemetry) using GCP Service Account authentication for real-time agent trajectory streaming and state persistence.
Google Cloud & Tech Stack Compliance Proof LLM Model: Google Gemini 3.5 Flash (via GenAI SDK / Antigravity SDK) for semantic version reasoning and self-healing recovery.
Agent Framework: Google Antigravity SDK (google-antigravity) & Google GenAI SDK (google-genai).
Google Cloud Infrastructure: Google Cloud Firestore (Database: (default), Collection: patchpilot_telemetry) used for real-time autonomous agent trajectory streaming and state persistence.
Backend Demo Proof: The demonstration video explicitly shows real-time telemetry synchronization on the Google Cloud Console Firestore dashboard in GCP project patchpilot-506816.
Challenges we faced Ensuring multi-step version upgrades maintain strict API backward compatibility without breaking application endpoints.
Managing enterprise security requirements by keeping GCP credentials isolated while maintaining uninterrupted, real-time Firestore trajectory streaming.
What we learned Structured multi-agent fleets significantly outperform monolithic LLM calls for complex DevSecOps remediation loops.
Real-time cloud telemetry streaming (via Firestore) is critical for building auditability and trust in autonomous agent execution.
Built With
- gemini-3.5-flash
- google-antigravity-sdk
- google-cloud
- google-cloud-firestore
- google-genai-sdk
- json
- osv-api
- pytest
- python
Log in or sign up for Devpost to join the conversation.