[/]patchward
examples

Real PRs, labelled literally.

Patchward has opened fix PRs against public repositories maintained by people with no reason to be kind about it. Outcomes below use literal labels — merged, closed, superseded, open. A PR that did not merge is not described as though it did.

outcome vocabulary

Four labels. No fifth, softer one.

mergedmaintainer follow-up shippedclosed — supersededopen
case · checkdmarc

The finding shipped. The PR did not.

checkdmarc#261 →– closed — superseded

checkdmarc#261 — Patchward flagged a Bandit B110 (try/except/pass) finding. Outcome label: closed — superseded. The PR itself was closed with unmerged commits; the maintainer reviewed it, narrowed the exception catch to UnicodeError, and shipped that fix in v5.17.3. The finding shipped; this PR did not.

verified 2026-08-20

This is the example worth reading closely, and it is why the label matters. A page willing to call this one "merged" would be a page you could not trust on anything else. The scanner found a real defect; the maintainer chose a narrower fix than the one proposed and shipped his own. That is a good outcome and an unmerged PR at the same time.

case · mpfb2

Merged, and linked so you can check.

mpfb2#398 →mpfb2#399 →✓ merged

2 security-fix PRs merged on mpfb2, both made under RepoMend's branch convention (RepoMend was Patchward's name until 2026-07-07): #398 (replaces assert statements and random.randrange in src/mpfb/entities/rig.py) and #399 (Bandit fixes in two scripts under src/loose_scripts/). Both merged by the mpfb2 maintainer on 2026-07-03. The commits are authored under the Symbiote git identity and signed off by Yehor Kaliberda. Whether each patch came out of the RepoMend pipeline end to end, or was written or reworked by hand, is not recorded, so it is not claimed.

verified 2026-10-05

What the links do and do not show. Both branches use the repomend/ prefix — RepoMend was Patchward's name until 2026-07-07 — and the commits are authored under the Symbiote git identity, signed off by Yehor. Whether each patch came out of the RepoMend pipeline end to end, or was written or reworked by hand, is not recorded, so this page does not claim it.

what you get in a pilot

The same artefacts, against your repository.

deliveryFree, self-hosted CLI. Install it yourself (`uv tool install patchward`) and run it with your own Anthropic API key and GitHub token — your code and credentials never pass through Patchward's own infrastructure. There is no hosted service, no paid tier, and no sales process.
branchpatchward/fix-<finding-id>
receiptevery gate on its own row — see /verification
your main branchuntouched — rollback is one git branch -D
Request a pilot →