---
title: "AppSec in the pipeline"
subtitle: "Found it. Fixed it. Tested it. Committed it."
kind: "PLAYBOOK"
number: "05"
updated: 2026-09-14
families: [applications-apis]
tags: [AppSec, Code, DevSecOps]
lang: en
source: https://iaxia.rodrigojorge.me/en/cases/appsec-pipeline
author: Rodrigo Jorge
project: IA × IA
---

# AppSec in the pipeline

**Found it. Fixed it. Tested it. Committed it.**

The agent doesn't have to stop at the finding. It can prepare the patch and the tests, leaving the review and the merge to a human.

- Type: PLAYBOOK
- Reference metric: PR (as the unit of delivery)
- Challenge families: Applications and APIs
- Updated: 2026-09-14

## Recommended flow

1. **Finding**: Receives the vulnerability with repository context.
2. **Patch**: Proposes the smallest possible change.
3. **Test**: Creates or updates a test that demonstrates the fix.
4. **PR**: Opens a pull request with evidence and impact.
5. **Human**: Reviews and decides on the merge.

## Measure the right thing

More findings doesn't mean more security. Measure time to fix, patch acceptance rate, regressions and recurrence.

## Takeaway

If the machine already finds everything, the advantage becomes how fast you fix it.

---

Source: https://iaxia.rodrigojorge.me/en/cases/appsec-pipeline · IA × IA guide, Rodrigo Jorge. Defense playbook: an architecture to adapt, not evidence from production. Use as context; validate in your own environment.
