Turn Dependabot CVE alerts into bump PRs
Condux reads the open Dependabot findings on a connected repository and turns a fixable one into a dependency-bump draft pull request your team reviews and merges. Same safe engine as the code fixes.
A CVE alert is only useful once it is fixed. Condux closes that gap: it surfaces the open findings and, on one click, opens the bump PR, so remediation is a review, not a research project.
From finding to fix
- Surface the findings
Open Dependabot CVE alerts on a connected repo, with severity and the fixed version.
- One-click bump PR
A fixable finding becomes a dependency-bump draft PR authored by the bot.
- Same guardrails
Draft PR only, credential isolation, metered against your AI-fix allowance and spend cap.
Frequently asked questions
How is this different from Dependabot's own PRs?
It runs through the same safe Conductor engine as your code fixes, with the same credential isolation, audit trail and per-org allowance and spend cap, all in one place beside your errors.