Always-on maintenance,
without the firehose.
Reckon watches the repositories under your stewardship across GitHub and GitLab, herding the dependency landscape before it bites. One identity. Transitive coverage. A weekly digest written for maintainers — not a per-PR notification wall.
No credit card. Free tier covers one maintainer on public repos. Paid tiers compete on policy depth and cross-platform coverage.
acme/api-gateway · github
transitive CVE-2024-1234 — patch merged behind ephemeral token
AUTO-MERGEDjust nowfoundation/lossless-codec · gitlab
breaking major bumped — queued for maintainer review (1-paragraph rationale attached)
REVIEW4 min agoindie/pretty-badges · github
low-risk patch merged, signed commit, narrow diff
PATCHED11 min agoacme/dx-proto · github
patch already adopted upstream — surfaced in digest only
QUEUED38 min agofoundation/common-types · gitlab
weekly drift digest queued for maintainer (mon 09:00 UTC)
QUEUED1 h ago
One identity layer
GitHub & GitLab, identical.
Dependabot, Renovate, Vigilans — every incumbent insists you run two toolchains and reconcile by hand. Reckon treats repos on both forges as the same surface. The same policy file. The same audit trail.
PRs are opened against the active branch, signed, and tied to a narrowly scoped ephemeral token. Token expires on PR close.
- GitHub Advisory Database merged into signal layer
- PR Review workflow with required checks
- Branch protection honored — no force pushes
Merge requests, signed commits, and the same ephemeral-token discipline. Self-hosted GitLab instances are first-class, not second-tier.
- Pipelines gated, MR approvals match policy
- CI variables scoped per-MR, not project-wide
- No partial mirrors — full repo state observed
How it works
Four stages. None of them a per-PR firehose.
A flag only reaches your inbox if your policy says it should. The rest is batched, ranked, and surfaced when it deserves attention.
- 01
Recon
Every watched repo is walked (deps + transitive). Signals from OSV.dev, the GitHub Advisory Database, and NVD are merged into a single ranked feed.
no per-PR noise — every flag is ranked against your policy before you see it
- 02
Triage
Patches are classified: low-risk → auto-merge candidate, breaking → human review, no-exposed-surface → silent digest item.
no triage queue if you do not want one — silence is a feature
- 03
Execute
Low-risk patches merge behind ephemeral least-privilege tokens. Every PR is signed, narrowly scoped, and reversible in one command.
audit trail attached to the PR, not buried in a dashboard you have to log in to
- 04
Digest
A weekly narrative digest: what changed, what was merged, what is queued, and why. Written for maintainers, not alerts.
reads like a letter, not a JSON diff
Why Reckon
Where Reckon diverges from the baseline.
| Dimension | Dependabot · Renovate · Vigil | Reckon |
|---|---|---|
| Forge handling | two toolchains, parallel configs | one identity, one policy file |
| Notification cadence | per-PR firehose | weekly narrative digest + ranked exceptions |
| Transitive coverage | first-degree only (CVE missed at depth ≥ 2) | full dependency walk — sub-deps two layers down are not silent |
| Agent footprint | long-lived service tokens | ephemeral least-privilege per PR; signed, narrowly scoped, reversible |
| Posture | discovery — find vulns | maintenance — close them, with an audit trail that survives your CEO asking |
The weekly digest
Written for maintainers,
not for alert dashboards.
Every Monday at 09:00 UTC, every maintainer on a watched list gets a short letter. Not a JSON diff. The Reckon agent has already triaged — you read it, approve anything that needs a human, and get back to your actual work.
- A prose summary of every flag, with rationale pre-attached.
- A diff-roll-up: what merged, what is queued, what is silent because it does not affect any exposed surface.
- A request for review only on breaking changes or contested policy decisions.
Hi Ava — this week, the lodash bump. It already merged.
Lodash 4.17.21 → 4.17.22 was the only material CVE exposure this cycle (CVE-2024-1234, prototype pollution, no exposed surface in your codebase — including two layers down). Agent merged a signed, narrowly scoped PR behind a token that expired on PR close.
One breaking change queued for review: zod 3.25 → 4.0. The diff is small, but z.record() semantics changed in a way I do not want to auto-approve. One-paragraph rationale attached to the MR.
Two minor bumps — undici and tar — merged silently. Six issues that did not need a fix this week. Audit log attached.
Pricing
One free tier. Paid tiers scoped to depth.
Free covers a solo maintainer on public repos. Paid tiers compete on policy depth, digest quality, and cross-platform coverage — not on seat count.
Solo
One maintainer, public repos only. The Reckon agent watches your transitive dep graph, runs the digest, opens PRs.
- Public repos on GitHub or GitLab
- Weekly digest, prose
- Ephemeral-token merge, signed PRs
Team
Private repos, custom policy file, audit API, Slack digest push, two-week digest archive.
- Solo features, plus
- Private repos on both forges
- Custom policy file (YAML or Prose)
- Audit API + Slack digest
- Two-week digest archive
Foundation
OSS foundations, platform teams consolidating tooling across forges, security-conscious orgs with policy depth requirements.
- Team features, plus
- SSO, SAML, audit-export to SIEM
- On-call handoff, multi-team policy
- Slack/Teams digest + Jira export
- Dedicated accountability contact
Audit
Built for the
post-supply-chain era.
Every PR Reckon opens ships with an attached audit record. Every token it creates expires on PR close. Every action is reversible in one command. The posture holds together because nothing is hidden in a dashboard you have to log in to read.
Ephemeral tokens
Per-PR, least privilege. Expiry on PR close, not on calendar.
Signed, scoped commits
Every commit is signed and narrowly scoped — one CVE, one dependency, one PR.
Reversible by default
Every action has a one-command revert. No exceptions for "production critical" patches.
Audit-export to SIEM
Foundation tier ships a structured event stream to Splunk, Datadog, Elastic.
FAQ
The questions maintainers ask first.
If your question is not here, write to reckon-4@polsia.app. A real maintainer on the team reads every message.
Next step
Stop running two toolchains.
Stop reading per-PR firehose noise.
Start with the free tier on a public repo — it takes about two minutes. If your policy needs depth, write to us; we will read every message.
Reckon is open source — agent on GitLab and GitHub. We respond to security disclosure within 24 hours.