Deployment.io

From security findings to verified fixes across two repositories.

Using a synthetic assessment of our own code, Deployment.io checked eight findings and rejected two deliberately incorrect claims. One selected remediation became two pull requests, opened seven minutes after the Task started.

By Ankit Arora, Founder

findings triaged against the code
8
deliberately incorrect findings rejected with code references
2
from Task start to pull requests in 2 repositories
7 min

The situation

We created a synthetic, nine-page assessment to evaluate how Deployment.io handles security findings in our own dashboard and API. It contained five valid findings, two deliberately incorrect claims, and one finding that required repositories outside the session.

The evaluation tested whether the workflow could distinguish valid findings from incorrect claims and carry a selected remediation through to reviewed code.

What Deployment.io did

We attached the report to a Deployment.io Assistant session connected to the dashboard and API repositories. Each finding was checked against the code.

  • Both deliberately incorrect findings were rejected with file and line references.
  • The finding involving other repositories was flagged for validation, with the required repositories identified.
  • Inaccurate descriptions of valid findings were corrected using the code.
  • One selected remediation became a specification, preserving its finding ID and verification criteria across the API and dashboard changes.

The Task opened two pull requests seven minutes after it started. The changes tightened message validation in the API and message handling in the dashboard, with regression tests covering both.

Before the pull requests opened, both repositories passed their builds and automated checks, including tests across 15 Go packages and 198 dashboard tests.

Verified outcome

The fixes for the selected remediation were reviewed and merged the same morning, then deployed to production.

The seven-minute figure measures Task start to the two pull requests. It excludes assessment, specification, engineer review, and production rollout.

Have security findings to resolve?

Share the findings, your deadline, and the systems involved. We will help scope the remediation and the evidence needed to verify it.