Dependency breakage, handled
When an SDK breaks your code, depfix ships the fix — verified by your own tests.
depfix watches your providers’ releases and API specs, finds the call sites a breaking change actually touches, writes the migration, and proves it against your test suite before a human ever reviews the PR.
async function moderate(input) {- const res = await openai.createModeration({ input });- return res.data.results[0];+ const res = await openai.moderations.create({ input });+ return res.results[0]; }The gap
Version bots tell you something broke. The fixing is still your week.
A bump PR knows a new major exists — it doesn’t know which of your call sites the breaking change touches, what the migration looks like, or whether the result still passes your suite. And provider-side changes, like a dated Stripe API version, never show up in a lockfile at all. That gap between “alerted” and “fixed” is where the engineering week goes. depfix exists to close it.
The pipeline
Six stages between a provider’s changelog and a reviewable PR
- 01
watch
Polls your providers' npm releases, GitHub tags, and OpenAPI specs on a schedule.
- 02
classify
Spec diffs are classified deterministically — no LLM, no guessing. Prose release notes pass a verbatim-evidence gate: no quote in the source, no classification.
- 03
scan
Finds the call sites the change actually touches, with per-site confidence.
- 04
fix
Writes the migration for affected files in a disposable copy of your repo.
- 05
verify
Runs your own test suite before and after. A fix that introduces a failure is reverted, not shipped.
- 06
pr
Opens one pull request with the diff, the evidence, and an honest confidence tier. A human merges — always.
Measured, not promised
The catch is the product: a bad fix never survives your tests
The fix that didn't make it
In a live run, the model's first attempt missed a response-shape change. The suite failed, the verifier attributed the failure to the exact file, and the edit was rolled back automatically. Nothing reached a PR.
The fix that did
With the failing test fed back, the corrected migration passed the full suite and shipped at HIGH confidence — the verdict you saw in the diff above.
- eval-corpus pass rate
- 90%
- LLM cost per verified fix
- $0.0016
- wall-clock, fix to verified
- 77s
Measured on our eval corpus and live fixture runs, September 2026.
Coverage
Two tiers, drawn exactly where verification is real
Fix + verify
Full pipeline: migration written, syntax-checked, proven against your suite.
- JavaScript / TypeScript
- Python
Scan + alert
Dependency declarations and import-level call sites flagged — you see exactly where you're affected.
- Java
- Kotlin
- Go
- Rust
- Ruby
- PHP
- C#
- Swift
We only auto-fix where we can verify locally. Everywhere else, depfix tells you precisely what a change touches instead of guessing at an edit nobody can test.
Trust posture
Built for teams that read the diff
A human merges every PR
Nothing lands on its own. The PR carries the evidence and an honest confidence tier.
Verified against your tests
Every fix runs your suite in a disposable checkout. Failures revert the edit.
Secrets never reach a model
Keyed, fail-closed redaction scrubs credentials from code before any LLM call.
Least-privilege by default
Per-repo, read-only GitHub tokens with short lifetimes. Your code stays yours.
Early access
We’re onboarding design partners now
If your product sits on the OpenAI, Stripe, or Anthropic SDKs, you’re who we built this for. Tell us about your stack and we’ll set up a scan.
Early access opens soon — this page is where it happens.