Reckon — open-source maintenance agent

Always-on maintenance,
without the firehose.

Reckon watches the repositories under your stewardship across GitHub and GitLab, herding the dependency landscape before it bites. One identity. Transitive coverage. A weekly digest written for maintainers — not a per-PR notification wall.

No credit card. Free tier covers one maintainer on public repos. Paid tiers compete on policy depth and cross-platform coverage.

reckon / activity
· 7 forges watched
  • acme/api-gateway · github

    transitive CVE-2024-1234 — patch merged behind ephemeral token

    AUTO-MERGEDjust now
  • foundation/lossless-codec · gitlab

    breaking major bumped — queued for maintainer review (1-paragraph rationale attached)

    REVIEW4 min ago
  • indie/pretty-badges · github

    low-risk patch merged, signed commit, narrow diff

    PATCHED11 min ago
  • acme/dx-proto · github

    patch already adopted upstream — surfaced in digest only

    QUEUED38 min ago
  • foundation/common-types · gitlab

    weekly drift digest queued for maintainer (mon 09:00 UTC)

    QUEUED1 h ago
$ reckon status — green

One identity layer

GitHub & GitLab, identical.

Dependabot, Renovate, Vigilans — every incumbent insists you run two toolchains and reconcile by hand. Reckon treats repos on both forges as the same surface. The same policy file. The same audit trail.

GitHub
primary

PRs are opened against the active branch, signed, and tied to a narrowly scoped ephemeral token. Token expires on PR close.

  • GitHub Advisory Database merged into signal layer
  • PR Review workflow with required checks
  • Branch protection honored — no force pushes
GitLab
equal coverage

Merge requests, signed commits, and the same ephemeral-token discipline. Self-hosted GitLab instances are first-class, not second-tier.

  • Pipelines gated, MR approvals match policy
  • CI variables scoped per-MR, not project-wide
  • No partial mirrors — full repo state observed
signal layer
OSV.devGitHub Advisory DBNVDtransitive-dependency walkpolicy-driven triage

How it works

Four stages. None of them a per-PR firehose.

A flag only reaches your inbox if your policy says it should. The rest is batched, ranked, and surfaced when it deserves attention.

  1. 01

    Recon

    Every watched repo is walked (deps + transitive). Signals from OSV.dev, the GitHub Advisory Database, and NVD are merged into a single ranked feed.

    no per-PR noise — every flag is ranked against your policy before you see it

  2. 02

    Triage

    Patches are classified: low-risk → auto-merge candidate, breaking → human review, no-exposed-surface → silent digest item.

    no triage queue if you do not want one — silence is a feature

  3. 03

    Execute

    Low-risk patches merge behind ephemeral least-privilege tokens. Every PR is signed, narrowly scoped, and reversible in one command.

    audit trail attached to the PR, not buried in a dashboard you have to log in to

  4. 04

    Digest

    A weekly narrative digest: what changed, what was merged, what is queued, and why. Written for maintainers, not alerts.

    reads like a letter, not a JSON diff

Why Reckon

Where Reckon diverges from the baseline.

DimensionDependabot · Renovate · VigilReckon
Forge handlingtwo toolchains, parallel configsone identity, one policy file
Notification cadenceper-PR firehoseweekly narrative digest + ranked exceptions
Transitive coveragefirst-degree only (CVE missed at depth ≥ 2)full dependency walk — sub-deps two layers down are not silent
Agent footprintlong-lived service tokensephemeral least-privilege per PR; signed, narrowly scoped, reversible
Posturediscovery — find vulnsmaintenance — close them, with an audit trail that survives your CEO asking

The weekly digest

Written for maintainers,
not for alert dashboards.

Every Monday at 09:00 UTC, every maintainer on a watched list gets a short letter. Not a JSON diff. The Reckon agent has already triaged — you read it, approve anything that needs a human, and get back to your actual work.

  • A prose summary of every flag, with rationale pre-attached.
  • A diff-roll-up: what merged, what is queued, what is silent because it does not affect any exposed surface.
  • A request for review only on breaking changes or contested policy decisions.
digest · week 32 · foundation/router-core
2026-08-03

Hi Ava — this week, the lodash bump. It already merged.

Lodash 4.17.21 → 4.17.22 was the only material CVE exposure this cycle (CVE-2024-1234, prototype pollution, no exposed surface in your codebase — including two layers down). Agent merged a signed, narrowly scoped PR behind a token that expired on PR close.

One breaking change queued for review: zod 3.25 → 4.0. The diff is small, but z.record() semantics changed in a way I do not want to auto-approve. One-paragraph rationale attached to the MR.

Two minor bumps — undici and tar — merged silently. Six issues that did not need a fix this week. Audit log attached.

— reckon agent · weekly digestsigned · audit ID rec-7f3a · 847 PRs opened · 0 incidents

Pricing

One free tier. Paid tiers scoped to depth.

Free covers a solo maintainer on public repos. Paid tiers compete on policy depth, digest quality, and cross-platform coverage — not on seat count.

Solo

Freeper maintainer

One maintainer, public repos only. The Reckon agent watches your transitive dep graph, runs the digest, opens PRs.

  • Public repos on GitHub or GitLab
  • Weekly digest, prose
  • Ephemeral-token merge, signed PRs

Team

Recommended
$49per maintainer / month

Private repos, custom policy file, audit API, Slack digest push, two-week digest archive.

  • Solo features, plus
  • Private repos on both forges
  • Custom policy file (YAML or Prose)
  • Audit API + Slack digest
  • Two-week digest archive

Foundation

Customstarting at $2k / month

OSS foundations, platform teams consolidating tooling across forges, security-conscious orgs with policy depth requirements.

  • Team features, plus
  • SSO, SAML, audit-export to SIEM
  • On-call handoff, multi-team policy
  • Slack/Teams digest + Jira export
  • Dedicated accountability contact

Audit

Built for the
post-supply-chain era.

Every PR Reckon opens ships with an attached audit record. Every token it creates expires on PR close. Every action is reversible in one command. The posture holds together because nothing is hidden in a dashboard you have to log in to read.

  • Ephemeral tokens

    Per-PR, least privilege. Expiry on PR close, not on calendar.

  • Signed, scoped commits

    Every commit is signed and narrowly scoped — one CVE, one dependency, one PR.

  • Reversible by default

    Every action has a one-command revert. No exceptions for "production critical" patches.

  • Audit-export to SIEM

    Foundation tier ships a structured event stream to Splunk, Datadog, Elastic.

FAQ

The questions maintainers ask first.

If your question is not here, write to reckon-4@polsia.app. A real maintainer on the team reads every message.

Next step

Stop running two toolchains.
Stop reading per-PR firehose noise.

Start with the free tier on a public repo — it takes about two minutes. If your policy needs depth, write to us; we will read every message.

Reckon is open source — agent on GitLab and GitHub. We respond to security disclosure within 24 hours.