Fix Pull Requests and Retests

How LaunchSafe turns a finding into a fix pull request you approve, and how a retest decides whether it is fixed.

Edit on GitHub

A fix pull request

Request

On a finding's Fix tab, request a fix pull request. Each one uses one of the month's fix pull requests from your plan. The fix is written against the branch that was scanned.

Review

LaunchSafe shows the patch, a summary and a pre-check. Nothing is pushed to GitHub yet. You can edit the title and description, approve, or discard.

Approve

Approving opens a pull request on a new branch named launchsafe/fix-.... It opens as a draft unless the project's policy says otherwise. The description says it was written by AI and needs review. Evidence stays behind your LaunchSafe sign-in and is not copied into it.

Merge

You merge it on GitHub, like any pull request. LaunchSafe never writes to a branch it did not create and never force-pushes.

An unapproved fix is discarded after 14 days. Approving needs write access to the repository, which you grant separately on GitHub. A project can be set to approve fixes automatically, but only when the fix's pre-check passed and write access is granted.

If a finding is fixed another way, accepted as a risk or marked a false positive while its pull request is open, LaunchSafe closes that pull request with a comment, and only pull requests it opened.

Retests

A retest checks one finding again. A retest starts when:

  • you press Retest on a finding or a fix;
  • a fix pull request merges, which queues a free retest of the merged code;
  • a later scan covered a finding and no longer reports it.

Only a retest that covered the finding can say fixed. A retest that finds it fixed closes the finding as verified fixed. A retest that finds it still there reopens a closed finding. A retest that could not cover it says why and changes nothing.

Retests are free within an allowance of 3 per finding per calendar month. The retest that follows a merge does not use it up.

Not covered

Fix pull requests and engine retests do not apply to Supabase settings findings. Running the check again is the retest. See Supabase.

On this page