Image: cdn.shopify.com · rights & removal
How River takes security work from a fix to merge
Reporting by Shopify EngineeringRead the original at shopify.engineering
Executive Summary
An AI agent named River operates within Shopify's monorepo to automate the remediation of dependency and first-party application vulnerabilities by integrating security workflows into the development pipeline. The system works from the root of the codebase, leveraging existing development environments and conventions to provide context for security tasks. River facilitates a workflow where it checks findings against live code and state before taking action, addressing issues in two primary ways: dependency upgrades via Pull Requests and application vulnerability fixes.
The process involves comparing a recorded work ledger against the current repository state, checking if vulnerabilities are still present, and then safely performing repairs or suggesting changes. This loop requires human engineers to make critical decisions regarding product behavior, risk acceptance, and merging fixes. Context is preserved through Slack threads documenting investigations and handoffs, allowing future agents and engineers to build upon previous work.
The operational results show significant impact: in the first eleven days of running the dependency workflow, open issue backlog decreased by approximately 70%, with two-thirds being direct merges. Furthermore, security merges through the freshness-gated queue increased from about 10% to 80%. The process highlights that agentic patching operates around the code difference (diff) and establishes a defensive asymmetry where defenders must preserve production behavior during fixes.
Facts Only
* A good patch is not the same as a fixed vulnerability.
* Shopify systems can generate dependency upgrades but cannot drive remediation to closure.
* River operates in Shopify's monorepo using shared development environments and conventions.
* River checks original findings against current code, updates patches safely, and brings in engineers for context-dependent decisions.
* The workflow involves checking the ledger against the live repository, pull request, and vulnerability tracker state before acting.
* For application vulnerabilities, River creates one Slack thread per finding; for dependency vulnerabilities, it groups related upgrades into a shared thread.
* River verifies if a vulnerability is still present before touching code to avoid altering production behavior unnecessarily.
* When an agent cannot make a decision, it hands off the context, current state, and required questions to human owners for approval and merging.
* After a merge, River checks the repository head and dependency graph before marking work as done.
* The dependency workflow reduced open issues by about 70% in the first 11 days.
* Security merges through the freshness-gated queue increased from 10% to 80%.
Full Take
The core innovation lies in operationalizing agentic patching by focusing on the transitions between states rather than just generating code changes. The system mitigates the risk of autonomous action by treating ledger entries as claims to be validated against the "operational truth" of the live repository, which prevents the agent from acting on stale premises. This establishes a critical principle: the process must prioritize preserving production-intended behavior above all else.
The divergence in workflow types—dependency upgrades versus application fixes—shows a nuanced approach to context management, using shared threads for complex investigative handoffs and distinct methods for managing automated steps (like rebase and CI retriggering). The narrative shifts from mechanical execution to human judgment at decision points, recognizing that when an agent encounters ambiguity regarding necessary product behavior, it must halt and present evidence for a human-based adjudication.
The pattern observed is the construction of trust through traceable evidence and deliberate handoffs. The system moves beyond simple automation by embedding accountability; the final "done" state requires agreement across multiple systems (source, default branch, tracker, ledger). This suggests that true agentic security success depends less on the agent's ability to execute code flawlessly and more on building a transparent, verifiable protocol for managing risk transitions. The implication is that future agentic workflows must embed rules directly into the code itself—making guarantees deterministic rather than relying solely on prompt-based judgment—to ensure resilience against inevitable shifts in context or evolving requirements.
From the original · Shopify Engineering
A good patch isn't the same as a fixed vulnerability. Shopify operates systems that can generate dependency upgrades and draft fixes for first-party code, but they can’t drive remediation to closure.Read the full story at shopify.engineering
Sentinel — provisional
No strong signs of machine writing were found in the source article. Provisional estimate, not a finding that a person wrote it.
LIKELY_HUMAN (confidence: 0.15)
This looks only at the wording of the original source article, not at this page's AI-written sections. A small local AI model made this estimate. It has not been checked against known human and machine texts, so treat it as provisional. It cannot show who wrote an article.
