Skip to content

CVE Fixer

There is a scheduled Ambient job that runs every night to detect CVEs in the repository. If CVEs are detected then a PR is created and pushed to the repository.

These are the scanned repositories:

These are the details of the scheduled job:

PropertyValue
NameCVE fixer (nightly)
Workflowcve-fixer
Schedule20 2 * * *
Inactivity Timeout36000 seconds (1 hour)
Runner TypeClaude Code
ModelClaude Opus 4.6

This is the initial prompt for the job:

Use the GitHub credentials that are provided in the integrations section. Find any CVEs in the repository dependencies and create a PR with the proposed fix in the repository by following the instructions in the CLAUDE.md in the repository.

The github credentials that are used for this job is a fine-grained personal access token that has the following characteristics:

Organization: eval-hub Repositories: all

PermissionAccess
Metadata (Required)Read-only
ContentsRead and write
Pull requestsRead and write