YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0069

Register entry

Google CodeMender upstreamed 72 security fixes in its first six months

Project
open-source projects (unnamed), codebases up to 4.5 million lines
Finder
Google CodeMender
Autonomy
agent proposes patches; every patch reviewed by a human researcher before submission
Evidence tier
Aggregate claim
Bounty
None published
Confidence
SINGLE

What happened

CodeMender fixes rather than finds: 72 security patches upstreamed over six months, each human-reviewed, with the model inside the harness moving from Gemini Deep Think to Gemini 3.5 Flash Cyber and then 3.8 Flash Cyber.

Credit as recorded: DeepMind announcement figure, corroborated across summaries; the announcement page was unopened by this desk. Date basis: Google Threat Intelligence Group report of 11 May 2026 describing CodeMender.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026