Skip to content
winfunc
Autofix
Available

From finding to a merge-ready pull request.

winfunc writes a focused patch in your codebase's own style and opens it as a pull request. Your engineers review, test, and merge through the process they already trust.

  1. acme
  2. /billing-api
  3. /Patches
  4. /WF-1042
Validated
src/services/invoices.ts+2−1
@@ -39,6 +39,7 @@ export async function getInvoice
39 export async function getInvoice(req: Request) {
40 const id = req.params.invoiceId;
41− return repo.findInvoice(id);
41+ const tenantId = req.auth.tenantId;
42+ return repo.findInvoice(id, { tenantId });
43 }
Checks3 / 3
  • Test suite214 passed
  • Exploit re-runrejected · 404 for tenant A
  • Lint and formateslint · prettier
View proofOpen pull request
Autofix · validated patchIllustrative data
  1. Minimal change, written in the repository's own style.
  2. The original exploit is run again against the patched build.
What it does

Capabilities.

  • Patches for validated security findings
  • Changes delivered as pull requests for review
  • Style-aware edits that follow surrounding code conventions
  • Job status tracking: pending, running, completed, failed
  • Per-patch cost tracking
  • Severity-based prioritization of what to fix first
  • Failed-job diagnostics with clear error messages
  • Organization-level controls for which repositories get patches
  • Re-review after the change to confirm the fix
Why it matters

Built for decisions, not queues.

01

Review in your workflow

Patches arrive as pull requests. Review the diff, run your tests, and merge or revise through your normal process. winfunc never merges to protected branches.

02

Context-aware changes

Each patch uses the finding's trace and the surrounding code to change only what the vulnerability requires, preserving expected behavior.

03

Verified, not assumed

After the change, winfunc re-runs its checks and marks the finding fixed only when the exploit path is closed.

04

Cost transparency

See what each patch job cost at the finding and organization level, next to the value of the fixes your team accepted.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.