Inspiration Modern software supply chains rely heavily on third-party dependencies. Manually tracking CVEs, determining compatible SemVer upgrades, and ensuring zero regressions creates a massive operational bottleneck for engineering teams. We built PatchPilot to transform reactive security into an autonomous, self-healing DevSecOps pipeline that fixes software vulnerabilities with zero human intervention.

What it does PatchPilot is an autonomous multi-agent fleet powered by Gemini 3.5 Flash and the Google Antigravity SDK, designed to monitor, remediate, validate, and stream execution state in real time:

Scout Agent: Scans project manifest files (requirements.txt) against the OSV.dev database to instantly detect real-time CVE and GHSA advisories.

Fixer Agent: Leverages Gemini 3.5 Flash for deep SemVer compatibility reasoning and API contract analysis to formulate optimal non-breaking patch proposals.

Validator Agent: Installs proposed patches in an isolated sandbox and executes pytest. If a regression is detected, it triggers an atomic rollback and initiates a closed-loop recovery with Gemini to self-heal the build.

Cloud Telemetry: Enterprise-ready logging engine streaming every decision trajectory and agent reasoning live to Google Cloud Firestore.

How we built it Multi-Agent Orchestration: Built using Python and the Google Antigravity SDK (google-antigravity) along with Google GenAI SDK (google-genai).

AI Engine: Powered by Google Gemini 3.5 Flash for intelligent version path reasoning and self-healing analysis.

Vulnerability Intelligence: Direct integration with the OSV.dev REST API for real-time CVE/GHSA lookup.

Sandbox & Validation: Isolated environment running automated pytest suites to guarantee contract stability before patch confirmation.

Google Cloud Infrastructure: Integrated Google Cloud Firestore (Database: (default), Collection: patchpilot_telemetry) using GCP Service Account authentication for real-time agent trajectory streaming and state persistence.

Google Cloud & Tech Stack Compliance Proof LLM Model: Google Gemini 3.5 Flash (via GenAI SDK / Antigravity SDK) for semantic version reasoning and self-healing recovery.

Agent Framework: Google Antigravity SDK (google-antigravity) & Google GenAI SDK (google-genai).

Google Cloud Infrastructure: Google Cloud Firestore (Database: (default), Collection: patchpilot_telemetry) used for real-time autonomous agent trajectory streaming and state persistence.

Backend Demo Proof: The demonstration video explicitly shows real-time telemetry synchronization on the Google Cloud Console Firestore dashboard in GCP project patchpilot-506816.

Challenges we faced Ensuring multi-step version upgrades maintain strict API backward compatibility without breaking application endpoints.

Managing enterprise security requirements by keeping GCP credentials isolated while maintaining uninterrupted, real-time Firestore trajectory streaming.

What we learned Structured multi-agent fleets significantly outperform monolithic LLM calls for complex DevSecOps remediation loops.

Real-time cloud telemetry streaming (via Firestore) is critical for building auditability and trust in autonomous agent execution.

Built With

  • gemini-3.5-flash
  • google-antigravity-sdk
  • google-cloud
  • google-cloud-firestore
  • google-genai-sdk
  • json
  • osv-api
  • pytest
  • python
Share this project:

Updates

Submission history