Patch

Generate candidate fixes for verified security findings. Consumes <repo>-triage.json (preferred; legacy TRIAGE.json accepted), a <repo>-security-audit.json report, *-vuln-findings.json (or legacy VULN-FINDINGS.json), *-pqc-facts.json (actionable first-party PQC blockers only), or an external vuln-pipeline results directory. Pipeline input is delegated to the execution-verified `vuln-pipeline patch` ladder; static-analysis input gets a per-finding patch subagent + independent reviewer and is written as inert diffs and git-am-ready patches for human review. Writes PATCHES/bug_NN/{patch.diff,patch.patch,patch_result.json}, PATCHES.md, and PATCHES.json. Use when asked to "fix the findings", "patch these vulns", "generate fixes", or "close the loop on triage".

openshift 0a9364a 40.8 KB Updated

File contents

openshift/traust/tree/main/harnessing/7-remediate/patch commit 0a9364aad9

Frequently asked questions

npx skillmds@latest add openshift/patch