Diese Seite ist nur auf Englisch verfügbar.
Issues and AI fix pull requests
Have Vulnara open an issue in your repository for each finding a scan reports, and let an AI agent open a pull request that fixes it.
When you start a scan you can ask Vulnara to turn its findings into work in your repository. Create issues opens an issue for each finding. Auto-remediate goes one step further: an AI agent works each issue and opens a pull request with a proposed fix, for you to review and merge.

What it is for
- Putting findings where your developers already work: the repository's issue tracker.
- Getting a first fix for a finding, such as a dependency version bump, without anyone writing it by hand.
- Tracking remediation from finding to merged fix, in the explorer and on the dashboard.
How it works
Issues
When a scan with Create issues finishes, Vulnara opens issues in the scanned repository:
- Code findings: one issue per distinct finding across the whole scan. A finding present on many commits is one issue.
- Vulnerable dependencies: one issue per library, listing every advisory against it. A library with many CVEs is one issue.
Each issue links to the finding in Vulnara and to the scan that produced it, and code issues link to the line in your repository. Issues carry the vulnara-ai label. A secret's value is never written into an issue: only its first few characters are shown, and the rest is masked.
Issue titles are stable across scans. Before opening an issue, Vulnara looks for an open issue with the same title and reuses it, so rescanning the same code does not flood your tracker with duplicates.
Fix pull requests
With Auto-remediate on, Vulnara comments on each issue that it is being remediated automatically, then runs an AI agent against a fresh clone of the repository. When the agent has a fix, it opens a pull request linked to the issue. The pull request description is the agent's own summary of the change, followed by a Vulnara footer that links to the scan, or the text of your own template if you set one.
Vulnara does not start a second fix for an issue that already has an open linked pull request.
Tracking
Vulnara records each finding's issue and pull request, with their state. You see them on the finding in the explorer, and you can filter the explorer by Issue: Open, Closed or No issue. The dashboard's Remediation panel counts findings, Issues opened, Fix PRs opened and Fix PRs merged.
What you can set
- Create issues: a switch in the scan form. Needs a git token.
- Auto-remediate: a switch in the scan form. Needs a git token and Create issues, because each fix is raised against its issue.
- Git token: the credential Vulnara uses to open issues and pull requests. It must be allowed to write issues and pull requests in the repository. See Connect GitHub or GitLab.
- Remediation templates: the Markdown body of the issues and pull requests Vulnara opens. There are three:
- Code finding issue: fields include
severity,scan_type,file,line,location,match(masked),branch,commit,repository_name,git_entity_name,source_link,scan_linkanddetected_at. - Vulnerable dependency issue: fields include
dependency,installed_version,highest_severity,advisory_count,advisories(a table of advisory, severity and fixed version),branch,commit,repository_name,git_entity_nameandscan_link. - Remediation pull request: fields include
ai_summary(the agent's description of its change),issue_number,repository_name,git_entity_name,fingerprint,dependencyandscan_link.
- Code finding issue: fields include
Write a field as {{ field_name }}. You can add one of the filters upper, lower, title or default('text'), for example {{ repository_name | upper }}. A field that does not exist renders as empty text. Templates are plain substitution: they cannot run code.
Do it
Open issues and fix pull requests for a scan
- In the web app at vulnara.rso.dev, choose New Scan and pick the repository.
- Select a Git Token.
- Switch on Create issues.
- Switch on Auto-remediate if you want fix pull requests too.
- Choose Start scan. Issues are opened once the scan finishes.
With the CLI, pass the same options to start_repository_scan:
vulnara start_repository_scan \
--repositoryId <repository id> \
--dockerScanToolId <scanner id> \
--gitTokenId <git token id> \
--createIssue --autoRemediateIn GraphQL, set createIssue and autoRemediate on startRepositoryScan. See Run a scan for the rest of the scan options.
Change the issue and pull request text
- Open Settings and choose Remediation templates.
- Expand Code finding issue, Vulnerable dependency issue or Remediation pull request.
- Write the body in Markdown. Insert fields with the chips under each editor.
- Choose Save templates.
Leave an editor empty to go back to Vulnara's default for that template.
In GraphQL, read the current templates with remediationTemplate and change them with setRemediationTemplate. A field sent as null restores the default. MCP (read only): remediation_template.
Review the pull request
A fix pull request is a proposal. Review it as you would a colleague's change, run your tests and merge it, or close it. Vulnara does not merge anything for you.
Good to know
- Issues and fix pull requests are opened on GitHub repositories.
- A scan that asks for issues but has no usable git token is refused.
- Templates replace only the body. The issue title and the
vulnara-ailabel stay the same, which is how Vulnara recognises its own issues on the next scan. - Changing templates needs the Editor role. Starting a scan needs the Editor role too. See Teams and roles.
- If the agent fails, no pull request is opened and the issue stays open for you to work. You can scan again with Auto-remediate to retry.
- If Vulnara cannot record an issue or pull request back against the finding, the issue or pull request itself is still created.