Skip to content

For single-package Node.js and TypeScript services on GitHub

Dangerous dependency vulnerabilities, fixed with evidence.

Kovo detects dangerous dependency vulnerabilities in GitHub-hosted Node.js repositories, generates the smallest viable fix, verifies it independently and opens a pull request.

How Kovo works

  1. Step 1

    Detect

    Kovo reads your npm or pnpm lockfile through the GitHub API, without cloning, and matches every resolved package against OSV and CISA KEV advisories. Findings that meet Kovo's P0 criteria (a malicious package, a known-exploited vulnerability in a production dependency, or a High or Critical production finding in a curated high-exposure package with a dangerous weakness type) trigger an alert right away, before any fix is attempted.

  2. Step 2

    Fix with the smallest change

    It tries the least invasive fix first: a lockfile-only update, then a direct patch or minor upgrade, then the nearest parent upgrade. Overrides, major upgrades and removals are prepared for human review, never merged automatically.

  3. Step 3

    Verify independently

    A separate, fresh sandbox installs the patched dependencies and runs checks derived from your own CI and scripts. Kovo first calibrates those checks by breaking your code on purpose, so it knows they can catch a real failure.

  4. Step 4

    Open a pull request

    Every pull request carries its verification evidence and the policy reasons behind it, including why it can or cannot be merged automatically.

Autopilot, only where policy allows it

Kovo Plus can merge eligible fixes for you: dependency-only patch and minor updates, and only when every deterministic policy gate passes. Agents propose patches; trusted infrastructure decides whether they merge.

  • A repository admin explicitly authorizes autopilot for each repository
  • Verification checks are calibrated and approved for that repository
  • Your branch protections and required checks pass on the exact commit
  • Major upgrades, overrides, removals and source changes always wait for a human
  • Repository, account and installation pauses stop merges immediately

What verification means, and what it does not

Verification is bounded evidence, not proof. Passing checks show that your build, type checks and tests still succeed with the fix applied; they cannot prove that arbitrary dependency code is safe, and Kovo does not promise zero regressions. Every pull request records exactly what was run, so you can judge the evidence yourself.

Repositories without tests can still be protected when other checks, such as a build or type check, calibrate successfully. Free fixes never call an AI model. Your source code is processed in short-lived sandboxes, and fixes are staged encrypted only until the pull request is published.

Built for your stack

Single-package Node.js and TypeScript services and Next.js apps on GitHub, using npm or pnpm with the public npm registry. Monorepos with workspaces, Yarn, Bun and private registries are not supported yet.

Protect a repository for free