Skip to content

Add a disable_remediation configuration field#15170

Merged
di merged 1 commit intogoogle:masterfrom
di:disable-remediation
Mar 16, 2026
Merged

Add a disable_remediation configuration field#15170
di merged 1 commit intogoogle:masterfrom
di:disable-remediation

Conversation

@di
Copy link
Copy Markdown
Member

@di di commented Mar 16, 2026

No description provided.

@DavidKorczynski
Copy link
Copy Markdown
Collaborator

/gcbrun skip

@di di enabled auto-merge (squash) March 16, 2026 14:50
@di di merged commit 4daf479 into google:master Mar 16, 2026
19 checks passed
is disabled, all disclosure notifications will not include any proposed code
changes. If enabled (default), proposed code changes and comments to remediate
bugs may be automatically included in disclosure that is private during the
embargo of each issue on a case-by-case basis basis.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like "basis" is repeated twice.

I'm guessing it involves LLM-generated patches OSS-Fuzz has experimented with but just out of curiosity was that feature already announced or is it in the works and hasn't been rolled out yet?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some early work here on automated remediation for OSS-Fuzz projects was announced last year: https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Got it. I saw the "codemender-patching@google.com" thing but those patches weren't posted fully automatically up until recently as far as I know. Either way as far as I understand with this setting it should be possible to opt out and it should cover use cases where it's not desirable for various reasons.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants