AI agents patch open‑source security

Updated: 2025.10.12 9D ago 2 sources
Google DeepMind’s CodeMender autonomously identifies, patches, and regression‑tests critical vulnerabilities, and has already submitted 72 fixes to major open‑source repositories. It aims not just to hot‑patch new flaws but to refactor legacy code to eliminate whole classes of bugs, shipping only patches that pass functional and safety checks. — Automating vulnerability remediation at scale could reshape cybersecurity labor, open‑source maintenance, and liability norms as AI shifts from coding aid to operational defender.

Sources

AI Slop? Not This Time. AI Tools Found 50 Real Bugs In cURL
EditorDavid 2025.10.12 78% relevant
Curl maintainer Daniel Stenberg says ~50 bug fixes were merged from reports generated via AI vulnerability scanners and validated by security researcher Joshua Rogers—parallel to the idea that AI systems can materially harden code (e.g., CodeMender submitting fixes) when integrated into real workflows.
Links for 2025-10-09
Alexander Kruel 2025.10.09 100% relevant
DeepMind blog announcement: “Introducing CodeMender… has already created and submitted 72 high‑quality fixes for serious security issues in major open‑source projects.”
← Back to All Ideas