p/pixeebot
Your automated product security engineer
Chris Messina
Pixeebot β€” Your automated product security engineer
Featured
51
β€’
Pixeebot is your automated product security engineer, reviewing your code and recommending changes via merge-ready pull requests to improve code security, performance, and quality.
Replies
Surag Patel
Maker
πŸ“Œ
πŸ‘‹Today is the big day for us at Pixee! After over a year building and hundreds of interviews with developers about their most frustrating topic – security – we are ready to launch Pixeebot. @nahsra and I embarked on this journey after being frustrated with the ever-increasing responsibilities faced by software developers today. Not only are they asked to build innovative features faster, they are expected to ensure it’s performant, usable and most critically, secure. Pixeebot was built to actually DO the work of security for developers. No more JIRA tickets, findings from scanners, or debating with security teams, just re-written code provided back, ready for a developer to review. What you can expect from us: - βœ… Merge-Ready Pull Requests. We aren’t giving you more work, we’re doing it for you. Just review + merge, done. - πŸͺ„ Auto-remediation from 3rd party scanners. Are you using another code scanner like Sonar, Semgrep, GitHub CodeQL? We’ll fix those findings too. - 🧠 AI used thoughtfully, not just as a blunt instrument. We leverage AI only where it adds value. If you’re not ready for it, you can disable it. - πŸ‘‚ Ears. We love feedback. The good, bad and ugly. During our private early access we've already got over 2,500 repositories using Pixeebot on GitHub. Our team continues to burn the midnight oil and we ship new features daily. We will extend our support to Gitlab and other languages (e.g. Javascript, Node, Go, etc.) in the future. Thank you so much! We look forward to your feedback and hope you’ll give Pixeebot a try. It feels amazing to take this first step in our journey and bring it to this community. πŸ’ͺ Also a huge shout out to @chrismessina for hunting us! πŸ™
Surag Patel
@patrycja_roszczyk thank you! Sure, email us at hi@pixee.ai
REPlexus - Customer Success-Led Growth
1 fix is better than 100 findings! Great job on this super-easy super-helpful GitHub app, @pixeebot Your blend of opensource-core boosted by AI makes this even more impressive.
Rosie Cunningham
Thank you @replexus! πŸ™
Rick Fan
Congrats, as a developer, this is exactly the feature I've been wanting since AI came around, but a key question is whether it can be reliable enough to catch at least 95% of the issues?
Surag Patel
@rick_fan - you're asking the exact right question. Before we even started building the product the first thing @nahsra and I researched is your question. We only wanted to build a product that we were confident could accurately and broadly fix the most critical and important vulnerabilities developers have been focused on the past decade. Given our prior experience building the most accurate security scanning tool in the market, we are also confident (and validated with our research) that we indeed fix the same. We're just getting started, but we already cover the bulk of the most critical and high vulnerabilities with many more coming. You can see all of it at our docs: https://docs.pixee.ai/codemods/o...
Rick Fan
@nahsra @sipat It's awesome, you make a great product!
Surag Patel
@rick_fan πŸ™
Garen Orchyan
Looks great, good job team. Best of luck today πŸ¦„β™₯️
Surag Patel
Thanks @orchyan! Love your concept too, I've followed along.
Naresh Meetei
This will be a game changer in product security. Cool product. Congrats on the launch.
Ghost Kitty
Comment Deleted
Surag Patel
@sewell_stephens thanks! We ❀️ snyk. The biggest difference is Snyk is built to find problems (and create JIRA tickets). Pixeebot will do the work of re-writing your code to fix the problems they find. So they work perfectly side-by-side.
Iuliu Pop
What's the coolest codemod fix you've seen in the wild?
Surag Patel
@iulspop my personal favorites are the most critical issues like SQL injection or command injection that we've seen merged. That said, we also have a couple that are going through the responsible disclosure process currently and will be published as CVEs soon! πŸ’ͺ
Rich Watson
Super cool, congrats!
Rosie Cunningham
Thank you @richw! Appreciate your support πŸ™
Udom Dwivedi
Congrats Pixee team. All the best.
Surag Patel
@udom_dwivedi thank you!
Kathan Desai
Amazing product, a must try for all! Congratulations on the product hun launch - Surag and team!
Surag Patel
@kathan_desai1 thanks for your support!
Manoj Agarwal
Love the value proposition. It's not only about finding the problem -- fixing and testing quickly is where most of the time is spent by the developers. Thank you, Surag and Pixee team, for bringing the innovative solution with Pixeebot.
Surag Patel
@manojagarwal thank you! Appreciate the feedback and support from Day 0.
Arshan Dabirsiaghi
Security has always yelled about things -- I should know, I spent my career doing the same -- but never fixed anything. I am so happy to show the world pixeebot! We help developers think less about security by issuing them PRs to fix the issues in their code. If you want better code and you never want to leave GitHub, this is your tool! Eager for your feedback!
Ryan Dens
πŸŽ‰ Pixeebot has been a massive timesaver on my projects. I particularly like it when it fixes findings from other security tools for me, so I don't have to!
Rosie Cunningham
Very glad to hear it, @ryan_dens! πŸ™Œ
Johnathan Gilday
How does Pixeebot use AI?
Surag Patel
@gilday In short, we use AI selectively & with purpose where it is truly additive to the user value, not as a blunt instrument. We aren't using AI for sake of saying it's AI, but there are many ways in which AI is uniquely helpful for this use case when used purposefully. Some of our "Pro" codemods leverage AI to add context to only make changes that appropriate for that precise code base/repo. Sometimes we use it to add commentary that explains why we made a change and provide additional context specific to your code. Many more features are on the way too...
Hashan Sandeepa
Looking valuable product.
Surag Patel
@hashan_sandeepa1 Thank you πŸ™ appreciate your comment.
Terra
Can you elaborate on the capabilities of third-party auto-remediation? Will Pixeebot be able to fix findings from all kinds of tools that create more work for developers to address?
Surag Patel
@terradactyl Yes! We've already built in the capability to take what a 3rd party scanner (e.g. Sonarqube, Semgrep or GitHub CodeQL) find and make a merge-ready pull request for the developer. This will save them MANY hours of time figuring out the problem, how to fix it and discussing it with the Security team. We will continue to expand this to many more tools as users request.
Nithin Raju
Wow, Congrats! I will try it out and give the product feedback.
Surag Patel
@nithin_raju1 appreciate the support! πŸ™Œ
Ghost Kitty
Comment Deleted
Vikas Aggarwal
Love how Pixeebot acts as your automated security engineer, offering code insights and merge-ready suggestions!
Chris Messina
Top Hunter
Hunter
Love the value prop here β€” not only does Pixeebot catch bugs when you submit PRs, but it also proposes changes to fix them! It's like having another code reviewer on your team. It can also look backwards across your codebase to find and propose fixes to bugs in your codebase. And it's better than just an LLM making up fixes; the team has its own proprietary system for finding and composing vetted solutions. You want Pixeebot watching your repo.