About

The missing layer between Dependabot and the merge button.

Klinn exists because of a gap nobody owned. Dependabot and Renovate open update PRs for free, scanners tell you which versions are risky, and registries block known-bad packages from installing. None of them merges anything. The pile of open update PRs on a busy repository is the visible symptom of that gap, and the incidents in our supply-chain attack timeline are the invisible one: teams either merge updates blind or not at all.

Klinn closes the gap by doing the work a careful engineer would do for every update, mechanically: wait out a cooldown, screen the version against the OSV advisory database, read the package's own published diff, run the repository's test suite against the update in a clean sandbox, repair the fallout when the bump breaks code, and merge only what the maintainer's policy allows. Every merge ships with a dossier of the evidence.

Principles

Proof over promises. The unit of trust is the dossier: which checks ran, what they found, what the suite said. Shadow mode runs the whole pipeline with zero write access so a repository owner can read that evidence before granting anything.

Security fails closed, billing fails open. Any failed check holds a merge and escalates to a human. A billing bug, by design, can never block a security fix.

Majors wait for you. No amount of green testing makes a breaking-by-contract upgrade an unattended decision. Majors are prepared, verified, and handed over.

Contact

Klinn is built by a small independent team. Write to hello@klinn.dev for anything: questions, pilots, corrections to the guides. The product runs as a GitHub App scoped to the repositories you pick.