Skip to content

Latest commit

 

History

1,086 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Drydock

Autonomous rescue for production-bound, AI-generated applications.

Drydock audits a public GitHub repository or ZIP export, explains concrete production-readiness risks in product language, builds a narrowly-scoped Fix Pack, verifies it where possible, and delivers the result as a GitHub pull request — never a push to main.

Product site: drydock.co.

This repository is the corresponding source for the hosted service (AGPL-3.0).

It is built for the moment after a Lovable, Bolt, Cursor, or hand-built prototype starts handling real users, credentials, payments, or deployments.

Why Drydock

Most scanners stop at a list of warnings. Drydock is built around a usable outcome:

  1. Inspect the application (static checks + LLM-assisted review).
  2. Explain the risk in product language and point at the relevant files.
  3. Generate the smallest safe change for supported problem classes.
  4. Verify in an isolated sandbox where the pipeline allows it.
  5. Open a reviewable pull request; optionally attach Proof-of-Exploit / Proof-of-Fix evidence for selected finding types (informational / gated by configuration, never a silent push).

You pay for the fix, not for a PDF of findings.

The free audit includes static checks for secrets, supported SQL, outbound URL, TLS, deserialization and file-path risks, local access-check inconsistencies, and project setup. Resolved npm/PyPI dependencies are also checked against the bundled CVE/GHSA catalog, using the same matcher as the local scanner. This stage sends no dependency inventory to OSV and still runs if the model is unavailable. The report records catalog sources, checksum, check time and coverage gaps; a version match does not establish runtime reachability. Catalog updates refresh cached dependency results without repeating model analysis, while keeping the original report intact.

The shared static engine includes a deterministic pattern-review agent: versioned CWE cards classify selected Python source observations. For supported FastAPI/Psycopg SQL, it collects HTTP origin, local flow, SQL slot roles and value constraints, then reports the remaining authorization and runtime prerequisites. It shares the local/browser/free-audit static engine and makes no model calls.

When available, the free audit also includes a limited model security preview of selected code (basis: static+preview). Static results remain available if the preview is unavailable or incomplete, including provider failures and usage limits. The report records which model analysis completed and any limits that affected it; its basis reflects the actual result.

The Fix Pack includes a separate full model review of authentication and security in addition to its supported fixes. Both scopes disclose source coverage and verification limits: neither promises review of every file, exhaustive vulnerability detection, or a validated readiness score.

Production today

Live on drydock.co with:

Area Status
Public GitHub + ZIP intake Live (SSRF-safe, hostile-archive checks)
Stacks Next.js, Vite + React, FastAPI
Audit Deterministic rules + LLM review; findings, provenance and verification limits
Fix Pack Secrets / config / selected static security rewrites → PR via GitHub App
Card payments ЮKassa (webhook is a hint; status/amount confirmed by server-side API)
Manual payments Bank transfer (operator-confirmed oracle)
Customer notify Email + Telegram (app/notify/), channel self-check on a timer
Ops Postgres queues, leases, /internal/stats, operator Telegram alerts (including paid backlog not draining)
Proof Registry + templates (e.g. secrets); soft/hard gate modes available

Release identity for a running host: GET /version (commit + source tree URL + CalVer tag). What the static audit can look for — every check, the rule ids it can emit, and what it does not resolve — is GET /v1/capabilities, served without authentication so it can be read before buying.

What Drydock deliberately does not claim

Read this before you pay — same boundaries the product enforces in code:

  • Not a penetration test. A source-supported finding is not automatically a runtime reproduction. Proof stages cover selected classes only.
  • Not every finding is auto-fixed. Unsupported or unsafe changes stay in the report; a Fix Pack is withheld or marked no_fix_needed when there is nothing safe to ship.
  • Public GitHub (or ZIP) only on public intake. Private repositories and non-GitHub hosts are out of scope for self-serve.
  • Verification can block delivery. If the sandbox is down or a patch looks like a regression, Drydock prefers not to open a PR over shipping an unverified change.
  • Payment rails are explicit. Card = ЮKassa. Bank transfer is manual. Historical mentions of other aggregators in old docs are not the live rail.
  • Continuous monitoring is built but not sold. The GitHub push webhook, the durable run queue and the findings diff all exist and are tested; MONITORING_FOR_SALE is False, and the webhook checks it before it looks up a subscription, so no push drives spend. Pricing, spend attribution and the cap are three decisions that have not been made — code in the tree is not a live offer.

Architecture (short)

public repo or ZIP
  → audit queue → static + LLM scan → findings + verification limits
  → (optional) paid Fix Pack → generate plan → sandbox / proof
  → GitHub App opens PR → customer notification

Design and security boundaries: docs/shipit-architecture.md. Payment rail note: docs/PAYMENT_RAIL.md. Longer operational history: docs/status-active.md (may lag; prefer this README and PAYMENT_RAIL.md for current rails).

Quick start (developers)

git clone https://github.com/aiagent2046-coder/shipit.git
cd shipit
python -m venv .venv
. .venv/bin/activate
pip install -e ".[dev]"
pytest -q

The test suite needs no cloud credentials. That is the honest local baseline.

Audits need a database. Without DATABASE_URL, the API can start, but POST /v1/audits returns 503 {"reason": "queue_unavailable"} — audits are queued jobs. Copy .env.example, set DATABASE_URL and API_KEY_PEPPER, then run migrations as documented in deploy docs. For a local development server, set ENVIRONMENT=development; the template selects production. See configuration requirements for the production and integration-specific fields.

Optional: LLM keys, GitHub App, sandbox runner, YOOKASSA_*, SMTP / Telegram. Without LLM keys the scan degrades to static-only (basis: static_only) rather than inventing coverage.

Local offline protection

The standalone install bundle provides drydock-local scan /path/to/project to check a folder with the shared static engine and local npm/PyPI CVE/GHSA catalog. watch observes source/catalog changes; history shows local scan summaries. No server, database service, LLM or network is needed for scanning. Catalog updates are explicit and pinned to a reviewed Shipit commit. See local setup, scope and exit codes.

Ownership of results

  • Audit report: GET /v1/audits/{id}?token=… (per-row access_token).
  • Fix Pack job: GET /v1/fixpacks/{id}?token=… (same model).
  • Lightweight poll after purchase: GET /v1/audits/{id}/fixpack-status (status + pr_url only).

A leaked UUID alone is not enough to read a report or job detail.

Deploy / ops (summary)

  • CalVer tags: vYYYY.MM.DD-N via deploy/scripts/tag-release.sh.
  • Production deploy is deliberate (workflow_dispatch or deploy/scripts/deploy-production.sh), not every push to main.
  • Timers: audit worker, Fix Pack processor, monitoring processor, notify channel check, reapers.
  • Operator alerts: Telegram (TELEGRAM_BOT_TOKEN + TELEGRAM_ADMIN_CHAT_ID), including failed Fix Packs and a stale paid backlog.

Contributing

Issues and pull requests are welcome. Keep changes small, add a focused test, and do not include credentials, customer archives, or live secrets.

Commits need a sign-off (git commit -s). There is no CLA and no copyright assignment. See CONTRIBUTING.md.

License

GNU Affero General Public License v3.0 — see LICENSE.

The hosted service at drydock.co meets the network-copyleft obligation by linking this repository from the product UI and by exposing the exact running tree through GET /version:

{
  "release": "<the commit answering this request>",
  "environment": "production",
  "source": "https://github.com/aiagent2046-coder/shipit/tree/<that commit>",
  "version": "<CalVer tag, e.g. v2026.08.28-10>",
  "built_at": "<ISO-8601 build timestamp>"
}

The shape is the point, not the values: the offer names the exact tree that served your request. Ask the endpoint for the current ones — a literal release written here would be wrong by construction, since the commit that updates it becomes the release after the one it names.

version and built_at are null on a source checkout rather than guessed — a truthful "this is not a built release", not an error.

If you are served a build whose source is not obtainable from that URL, that is both a licence problem and a bug — please report it.

About

Autonomous rescue for vibe-coded apps: production audit + verified Fix Packs delivered as PRs

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages