Skip to content

Fix a finding

emendant fix turns scan findings into patch files. It does not edit your source files or Git history. You review and apply each patch yourself.

Start with a dry run:

Terminal window
npx emendant fix --dry-run

This prints each candidate diff without writing .emendant/. It also does not run your repository’s checks, install a target SDK release, or call a model. Emendant applies the edits in memory and matches the workspace again, so a successful preview is structurally checked.

A preview shows what Emendant plans to change. It does not show that the result compiles, passes tests, or works with the target SDK release.

Run fix mode without --dry-run when the preview is correct:

Terminal window
npx emendant fix

Emendant writes the result below .emendant/:

.emendant/
report.json
report.md
patches/
<finding>.patch
all.patch

all.patch is present only when two or more offered patches also pass together.

The command first checks every patch in memory. It then finds a typecheck and test command that the repository already owns. When it finds checks, it runs them against a patched copy outside your working tree. For a pending upgrade, it also uses your package manager to install the target SDK release into a source-free preparation directory before it checks the copy.

Emendant does not invent a command when the repository has no typecheck or test script. It still writes a patch that passes the structural check, and grades it structurally checked. This is a usable patch with limited evidence, not a failure.

Open .emendant/report.md, then read the header and diff inside the patch. Each patch has one of four grades:

Grade What Emendant proved
test verified The repository’s tests passed with the patch. A selected typecheck also passed.
typechecked The repository’s typecheck passed. No test command ran.
structurally checked The edits applied and matching found no new affected use. No code compiled or ran.
unchecked Emendant could not obtain structural, type, or test evidence.

A patch can be withheld after Emendant creates its edits:

  • failed means the baseline was green and the patched copy was red, or the structural check found that the patch did not do what it claimed. This result is about the patch.
  • inconclusive means the machine could not decide. For example, the baseline was already red, an install did not complete, or a command timed out. This result is not evidence that the patch is wrong.

The report names the checks that ran, where they came from, and why a patch was written or withheld. See the CLI reference for flags that override check discovery or keep the verification copies.

Emendant writes one patch per finding. When two or more offered patches also pass together, it writes all.patch.

  • Use a per-finding patch when you want to apply one change.
  • Use all.patch when you want every offered change. Do not apply all of the per-finding patches one after another. Nearby patches can share context and fail when applied in sequence.

Review the diff before you apply it:

Terminal window
git apply --check .emendant/patches/all.patch
git apply .emendant/patches/all.patch

For one finding, replace all.patch with that patch’s filename. git apply --check confirms that the patch still fits your current files. git apply makes the source changes. Review the resulting Git diff and run any additional checks your project needs.

Most patches use a deterministic transform on your machine. They need no model, account, or model request.

Some migrations have no safe mechanical transform. These findings stay unfixed unless you name a model provider:

Terminal window
npx emendant fix --model-provider codex # the login your Codex CLI already has
npx emendant fix --model-provider claude # the login your Claude Code CLI already has

Without --model-provider, and without a provider in emendant.json, nothing is sent anywhere. When you name a provider, Emendant sends a bounded excerpt of the matched file directly from your machine to that provider. The result goes through the same bounds and verification as a deterministic patch. The report and patch header state that a model wrote it.

See Security and privacy for the data boundary and the configuration reference for persistent provider and verification settings.