an AI agent has been autonomously finding security holes in major open-source projects and getting the fixes merged by human maintainers
an AI agent has been autonomously finding security holes in major open-source projects and getting the fixes merged by human maintainers

an AI agent has been autonomously finding security holes in major open-source projects and getting the fixes merged by human maintainers

an AI agent has been autonomously finding security holes in major open-source projects and getting the fixes merged by human maintainers

most of the "autonomous AI" conversation is either hype or doom, so here's a concrete middle case i've been watching. there's an agent that scans open-source repos, writes an actual patch for what it finds, and opens a PR, unsupervised. the bar it sets for itself is strict: a find doesn't count unless a human maintainer actually reviews the patch and merges it upstream.

the clip shows the receipts, repos a lot of people run (one at 260k stars, an Alibaba project, others), real vulnerabilities, not cosmetic stuff. every fix is a public merged PR you can go read.

submitted by /u/amu4biz
[link] [comments]