Private betaNow watching TypeScript repositories on GitHub
Your code didn't change.The API did.
Mendward watches the APIs and SDKs your code depends on, proves which lines a change breaks, writes the smallest safe fix, runs your own checks, and opens a pull request with the evidence.
The upstream example on this page, a Ledger API renaming entryRef to entry_id, is synthetic. It mirrors a real benchmark case.
How an upstream change breaks production silently
- It compiles.
- Tests pass.
- Production breaks.
- A customer finds it first.
Nothing in your repository changed, so nothing in your pipeline looked. The provider renamed one response field on a Tuesday.
Every provider.Every version.Every call site.
Nobody reads them all.
Mendward does, and only tells you about the ones that reach your code.
Sixty-eight seconds, from the crack to the mend.
The launch film. Every frame is a function of time, every sound is synthesised, and every hit lands on the beat.
Detect the change. Prove the impact. Ship a verified fix.
Six stages, in a fixed order, recorded as data. Each one hands the next a fact, never a guess.
- 01
Ingest
Fetch the upstream source and keep the exact bytes.
Mendward fetches the published specification, SDK release or schema, stores the raw bytes with a SHA-256, and normalises it. The fingerprint is the only identity a fetch has.
- 02
Detect
Diff it, and explain why each change matters.
A semantic diff against the last observation produces typed changes with evidence: what moved, where in the document, how severe, and the reason for that severity.
- 03
Analyze
Prove which lines of your code it reaches.
Mendward builds a real program from your repository and follows symbols through imports, aliases, wrappers and re-exports. Every finding carries a file, a line, a column and the evidence for it.
- 04
Migrate
Write the smallest safe patch.
Deterministic recipes run first. A model is used only for what no recipe claims, and its hunks are labelled. Every changed line must be attributable to a specific edit, or the patch is refused.
- 05
Verify
Run your own checks in a sealed container.
Your typecheck, build and tests, as your repository declares them, in a container with no network and a read-only worktree. A check that did not run says so, forever.
- 06
Pull request
Open a pull request a reviewer can trust.
The diff, the evidence, the verification results, what to doubt and how to undo it. One idempotency key per change set, so a retry can never open a duplicate. You merge. Mendward never does.
Ingest
Mendward fetches the published specification, SDK release or schema, stores the raw bytes with a SHA-256, and normalises it. The fingerprint is the only identity a fetch has.
- Fetched
- 2026-10-05 09:14:02 UTC
- HTTP
- 200, 412 KB, ETag "7c1e"
- SHA-256
- 9f3c4a1e...b07de21a
- Contract
- OpenAPI 3.0, 86 operations, 140 schemas
- Previous
- 41aa09c2...5e1f7730
The fingerprint is the fetch's only identity. Same bytes, no new run.
Detect
A semantic diff against the last observation produces typed changes with evidence: what moved, where in the document, how severe, and the reason for that severity.
property_renamedBreakingLedgerEntry.entryRef to LedgerEntry.entry_id
A response property your code may read no longer exists under its old name. Direction: response.
#/components/schemas/LedgerEntry/properties
property_addedAdditiveLedgerEntry.posted_at
New optional field. Nothing to migrate.
Analyze
Mendward builds a real program from your repository and follows symbols through imports, aliases, wrappers and re-exports. Every finding carries a file, a line, a column and the evidence for it.
src/ledger.ts:42:21HIGHconst ref = row.entryRef;- Resolved by the type checker to
LedgerEntry - Import traced to
@ledger/sdk
src/report/export.ts:18:9HIGHconst { entryRef } = entry;- Destructured read of the renamed field
scripts/legacy-fmt.ts:7:14LOWlog("entryRef missing");- Text match only. A string that contains the name is not proof it is read.
Migrate
Deterministic recipes run first. A model is used only for what no recipe claims, and its hunks are labelled. Every changed line must be attributable to a specific edit, or the patch is refused.
41export function toRow(row: LedgerEntry) { 42 const ref = row.entryRef;42 const ref = row.entry_id;43 return { ref, amount: row.amount }; 44}
Verify
Your typecheck, build and tests, as your repository declares them, in a container with no network and a read-only worktree. A check that did not run says so, forever.
Pull request
The diff, the evidence, the verification results, what to doubt and how to undo it. One idempotency key per change set, so a retry can never open a duplicate. You merge. Mendward never does.
Migrate Ledger API: entryRef renamed to entry_id #128
- Upstream change
- Why this repository
- What changed
- Verification: 4 ran, 1 skipped with reason
- Known uncertainty and manual review
- How to undo this
- Evidence and confidence: HIGH
Mendward opens it. You merge it.
No affected code. No pull request.
A tool that opens forty pull requests gets uninstalled. Mendward opens one where your code reads the thing that changed, and stays silent everywhere else.
src/ledger.tsreads entryRefsrc/report/export.tsreads entryRefsrc/api/client.tssrc/routes/entries.tstest/ledger.test.tspackage.json
src/pages/index.tsxsrc/components/Hero.tsxsrc/lib/analytics.tssrc/styles/site.cssnext.config.tspackage.json
Nothing here reads entryRef. Checked, recorded, and not your problem.
No percentages. A level, and the signals behind it.
A percentage reads like a measurement nobody took. Mendward reports LOW, MEDIUM or HIGH, computed two ways and the lower one wins: a cap from the worst negative signal, a raise from the best positive one. Try it.
The lower of the two wins. Two independent signals put it at HIGH, and nothing argues against it.
Not a vendor list.
A customer should be able to point Mendward at an API it has never heard of. Every source is compiled into one contract model, and everything after that is shared, so a new company never needs new code.
How any source becomes a pull request- OpenAPILive
- npmIn development
- PyPIIn development
- GraphQLIn development
- ProtobufIn development
- JSON SchemaIn development
- GitHub releasesIn development
- ChangelogIn development
- Your webhookIn development
One contract model
Provider-neutral. The diff never learns who published it.
- Semantic changes
- Impact
- Migration
- Verified pull request
Live today Preset in development. Names are plain text: no logos, no implied partnership.
Built to be trusted with private code.
Mendward will hold some of the most sensitive repositories a company has. Security is not a feature list here. It is a set of properties, each one proven by a test that fails if it stops being true.
- Four GitHub permissions. contents read, contents write, pull requests write, metadata read. Everything else is on a forbidden list that fails the build.
- Tokens are never stored. Installation tokens are minted on demand, cached in memory for at most an hour, and never written to a database.
- Tenants cannot see each other. Row-level security is enabled and forced on every tenant table, and a cross-tenant request gets the same 404 as a real miss.
- Your code never reaches a prompt as instructions. Customer source and committed secrets are kept out of model requests, proven by 45 tests on that boundary.
--rm --initgone when it exits--read-onlythe root filesystem cannot be written--cap-drop ALLno Linux capabilities at all--security-opt no-new-privilegesnothing can escalate--network noneno way out--pids-limit --memory --cpushard ceilings, swap included--ulimit core=0no secret-bearing core dumps--mount /work,readonlyyour code, read-only--env NAME=valueexplicit values, never inherited
Twelve things Mendward will not do.
These are the product. A change that breaks one is a regression, whatever else it improves.
- 1
It will not report a check as passed when it did not run.
A skipped check is recorded as skipped, with the reason, in the database, the interface and the pull request. It never turns green later.
- 2
It will not output a confidence percentage.
You get a level, LOW, MEDIUM or HIGH, plus every signal that produced it. Three weak findings and one strong one do not average to 72%.
- 3
It will not fabricate a number.
Counts, lines, durations and outputs come from a measurement a code path performed. An empty value means nothing was measured, never zero.
- 4
It will not touch a line no edit claimed.
Every changed line is attributed to a specific edit and checked against an independently computed diff. Reflowed whitespace is refused outright.
- 5
It will not hide a repository it could not verify.
If verification could not run, the pull request says so on its first screen, not in a footnote.
- 6
It will not read your repository as instructions.
A model sees repository text only in a delimited data channel, with a static system prompt, provenance on every fragment and visible truncation.
- 7
It will not ask GitHub for a permission it cannot justify.
Four permissions, each traced to one product behaviour. Anything it might be tempted to add is named in a forbidden list that fails the build.
- 8
It will not run your code outside a sealed container.
No network, a read-only worktree, dropped capabilities and hard resource ceilings. Production refuses to start on an unpatched runtime.
- 9
It will not forward a secret into a container, an error or a log.
Environment is passed by explicit value only, and 23 control-plane secret names are refused even when asked for.
- 10
It will not delete or edit an audit row.
The audit trail is append-only at the database level and hash-chained per organization, so an edit breaks the chain.
- 11
It will not tell you your code is safe when it does not know.
An empty set of findings is a hard failure, not a reassuring empty plan. Not knowing is reported as not knowing.
- 12
It will not average.
If four places need a human, it says four places need a human, and names them.
All twelve, with the reasoning behind each.
Read the commitments
Every number on this page came from a run.
Mendward is built the way it behaves. The release gate tests itself before it tests anything else, and refuses to start if its own pass and fail logic is wrong.
- Unit tests
- Integration tests
- Browser tests
Measured 2026-10-04 at commit 596203d, against real Postgres and a real container runtime.
- PASS
lint0 errors5.5s - PASS
typecheck:packagesclean0.8s - PASS
typecheck:webclean25.7s - PASS
test:gate50 passed11.6s - PASS
test:unit2,657 passed in 93 files60.1s - PASS
db:verify20 tables, 8 functions, 0 violations1.8s - PASS
test:integration543 passed in 36 files266.7s - PASS
build:webproduction build58.3s - PASS
test:e2e20 Playwright specs35.6s
9 passed, 0 failed, 0 skipped, 9 total
A sample of real test names from the repository at 596203d. The total is the gate's own.
Asked, and answered plainly.
The short version of what Mendward is, what it touches, and what it will not do. The pages below show the detail.