AI security review before merging runtime behavior changes
Author: jean-micheletCreated Sep 14, 2026Updated Sep 14, 2026
Prerequisites
- I have written a descriptive issue title
- I have searched existing issues to ensure the issue has not already been raised
Issue
I noticed that investigating and fixing security issues can be a significant burden for maintainers.
Following the posts of Ulises Gascón, I can see that despite the noise of false positives, a significant number of reported issues are legitimate.
Could we add an AI security review before merging PRs that change Fastify's runtime behavior? The goal would be to catch some of these legitimate issues earlier, before they are later discovered and reported automatically by external agents.
Some lead maintainers (cc @Eomm @mcollina) may also be able to get access through OSS programs:
Source: fastify/fastify