Tools AI-Found Vulnerability Register aifv-0069
Register entry
Google CodeMender upstreamed 72 security fixes in its first six months
- Project
- open-source projects (unnamed), codebases up to 4.5 million lines
- Finder
- Google CodeMender
- Autonomy
- agent proposes patches; every patch reviewed by a human researcher before submission
- Evidence tier
- Aggregate claim
- Bounty
- None published
- Confidence
- SINGLE
What happened
CodeMender fixes rather than finds: 72 security patches upstreamed over six months, each human-reviewed, with the model inside the harness moving from Gemini Deep Think to Gemini 3.5 Flash Cyber and then 3.8 Flash Cyber.
Credit as recorded: DeepMind announcement figure, corroborated across summaries; the announcement page was unopened by this desk. Date basis: Google Threat Intelligence Group report of 11 May 2026 describing CodeMender.
Sources
- Google DeepMind, Introducing CodeMenderdeepmind.google/blog/introducing-codemender-an-ai-agent-for-…
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026