Fix a finding
emendant fix turns scan findings into patch files. It does not edit your source files or Git history. You review and apply each patch yourself.
Preview the changes
Section titled “Preview the changes”Start with a dry run:
npx emendant fix --dry-runThis prints each candidate diff without writing .emendant/. It also does not run your repository’s checks, install a target SDK release, or call a model. Emendant applies the edits in memory and matches the workspace again, so a successful preview is structurally checked.
A preview shows what Emendant plans to change. It does not show that the result compiles, passes tests, or works with the target SDK release.
Generate the patches
Section titled “Generate the patches”Run fix mode without --dry-run when the preview is correct:
npx emendant fixEmendant writes the result below .emendant/:
.emendant/ report.json report.md patches/ <finding>.patch all.patchall.patch is present only when two or more offered patches also pass together.
The command first checks every patch in memory. It then finds a typecheck and test command that the repository already owns. When it finds checks, it runs them against a patched copy outside your working tree. For a pending upgrade, it also uses your package manager to install the target SDK release into a source-free preparation directory before it checks the copy.
Emendant does not invent a command when the repository has no typecheck or test script. It still writes a patch that passes the structural check, and grades it structurally checked. This is a usable patch with limited evidence, not a failure.
Read the evidence
Section titled “Read the evidence”Open .emendant/report.md, then read the header and diff inside the patch. Each patch has one of four grades:
| Grade | What Emendant proved |
|---|---|
test verified |
The repository’s tests passed with the patch. A selected typecheck also passed. |
typechecked |
The repository’s typecheck passed. No test command ran. |
structurally checked |
The edits applied and matching found no new affected use. No code compiled or ran. |
unchecked |
Emendant could not obtain structural, type, or test evidence. |
A patch can be withheld after Emendant creates its edits:
failedmeans the baseline was green and the patched copy was red, or the structural check found that the patch did not do what it claimed. This result is about the patch.inconclusivemeans the machine could not decide. For example, the baseline was already red, an install did not complete, or a command timed out. This result is not evidence that the patch is wrong.
The report names the checks that ran, where they came from, and why a patch was written or withheld. See the CLI reference for flags that override check discovery or keep the verification copies.
Choose a patch
Section titled “Choose a patch”Emendant writes one patch per finding. When two or more offered patches also pass together, it writes all.patch.
- Use a per-finding patch when you want to apply one change.
- Use
all.patchwhen you want every offered change. Do not apply all of the per-finding patches one after another. Nearby patches can share context and fail when applied in sequence.
Review the diff before you apply it:
git apply --check .emendant/patches/all.patchgit apply .emendant/patches/all.patchFor one finding, replace all.patch with that patch’s filename. git apply --check confirms that the patch still fits your current files. git apply makes the source changes. Review the resulting Git diff and run any additional checks your project needs.
Fixes written in two ways
Section titled “Fixes written in two ways”Most patches use a deterministic transform on your machine. They need no model, account, or model request.
Some migrations have no safe mechanical transform. These findings stay unfixed unless you name a model provider:
npx emendant fix --model-provider codex # the login your Codex CLI already hasnpx emendant fix --model-provider claude # the login your Claude Code CLI already hasWithout --model-provider, and without a provider in emendant.json, nothing is sent anywhere. When you name a provider, Emendant sends a bounded excerpt of the matched file directly from your machine to that provider. The result goes through the same bounds and verification as a deterministic patch. The report and patch header state that a model wrote it.
See Security and privacy for the data boundary and the configuration reference for persistent provider and verification settings.