When remediation starts
With the default remediation hook enabled, assigning a vulnerability to remediation-agent starts a run. In the default setup, the triage agent makes this assignment when it determines that remediation can proceed. The agent receives the vulnerability, the triage investigation, and evidence from the run that discovered the issue. It can also use your Asset Map and connected integrations to understand the affected systems and their dependencies.What the agent produces
remediation-agent produces remediation steps. Each step describes a concrete change needed to address the vulnerability. Steps can include:- Code changes: a GitHub pull request containing a proposed fix.
- Infrastructure changes: instructions for updating cloud resources, permissions, or service configuration.
- Work for your team: actions that require someone with the necessary access or context.