Show HN: Patchwork – Open-source framework to automate development gruntwork

github.com

116 points by rohansood15 a month ago

Hi HN! We’re Asankhaya and Rohan and we are building Patchwork.

Patchwork tackles development gruntwork—like reviews, docs, linting, and security fixes—through customizable, code-first 'patchflows' using LLMs and modular code management steps, all in Python. Here's a quick overview video: https://youtu.be/MLyn6B3bFMU

From our time building DevSecOps tools, we experienced first-hand the frustrations our users faced as they built complex delivery pipelines. Almost a third of developer time is spent on code management tasks[1], yet backlogs remain.

Patchwork lets you combine well-defined prompts with effective workflow orchestration to automate as much as 80% of these gruntwork tasks using LLMs[2]. For instance, the AutoFix patchflow can resolve 82% of issues flagged by semgrep using gpt-4 (or 68% with llama-3.1-8B) without fine-tuning or providing specialized context [3]. Success rates are higher for text-based patchflows like PR Review and Generate Docstring, but lower for more complex tasks like Dependency Upgrades.

We are not a coding assistant or a black-box GitHub bot. Our automation workflows run outside your IDE via the CLI or CI scripts without your active involvement.

We are also not an ‘AI agent’ framework. In our experience, LLM agents struggle with planning and rarely identify the right execution path. Instead, Patchwork requires explicitly defined workflows that provide greater success and full control.

Patchwork is open-source so you can build your own patchflows, integrate your preferred LLM endpoints, and fully self-host, ensuring privacy and compliance for large teams.

As devs, we prefer to build our own ‘AI-enabled automation’ given how easy it is to consume LLM APIs. If you do, try patchwork via a simple 'pip install patchwork-cli' or find us on Github[4].

Sources:

[1] https://blog.tidelift.com/developers-spend-30-of-their-time-...

[2] https://www.patched.codes/blog/patched-rtc-evaluating-llms-f...

[3] https://www.patched.codes/blog/how-good-are-llms

[4] https://github.com/patched-codes/patchwork

[Sample PRs] https://github.com/patched-demo/sample-injection/pulls

meiraleal a month ago

PR reviews are the one thing you sure don't want a LLM doing.

  • Carrok a month ago

    Please elaborate.

    While obviously a LLM might miss functional problems, it feels extremely well suited for catching “stupid mistakes”.

    I don’t think anyone is advocating for LLMs merging and approving PRs on their own, they can certainly provide value to the human reviewer.

    • cuu508 a month ago

      They can lull the human reviewer into a false sense of security.

      "Computer already looked at it so I only need to glance at it"

      • throwthrowuknow a month ago

        I don’t know what your process is but if someone else has reviewed a PR before I take my turn I don’t ignore the code they’ve looked at. In fact I take the time to review both the original code as well as their comments or suggestions. That’s the point of review after all, to verify the thinking behind the code as well as the code itself and that applies equally to thoughts or code added by a reviewer.

    • spartanatreyu a month ago

      > LLM [...] feels extremely well suited for catching “stupid mistakes”.

      No.

      Linters are extremely well suited for catching stupid mistakes.

      LLMs are extremely well suited for the appearance of catching stupid mistakes.

      Linters will catch things like this because they can go through checking and evaluating things logically:

      > if (

      > isValid(primaryValue, "strict") || isValid(secondaryValue, "strict") ||

      > isValid(primaryValue, "loose" || isValid(secondaryValue, "loose"))

      > //...............................^^^^ Did we forget a closing ')'?

      > ) {

      > ...

      > }

      LLMs will only highlight exact problems they've seen before, miss other problems that linters would immediately find, and hallucinate new problems altogether.

      • luckilydiscrete a month ago

        While true in a subset of problems, linters will also miss stupid mistakes because not everything is syntactical.

        AI for example can catch the fact that `phone.match(/\d{10}/)` might break because of spaces, while a linter has no concept of a correct "regex" as long as it matches the regex syntax.

        I don't think anyone is arguing that replacing linters with AI is the answer, instead a combination of both is useful.

      • rohansood15 a month ago

        Linters are great at finding syntactical errors like the case you mentioned. But LLMs do a better job at finding logical flaws or enforcing things like non-syntactic naming conventions. The idea is not to replace linters, but to complement them. In fact, one of the flows we're building next is fixing linting issues that linters struggle to fix automatically.

  • rohansood15 a month ago

    I agree and disagree. You definitely need someone competent to take a look before merging in code, but you can do a first pass with an LLM to provide immediate feedback on any obvious issues as defined in your internal engineering standards.

    Especially helpful if you're a team with where there's a wide variance in competency/experience levels.

    • aaomidi a month ago

      Until that immediate feedback is outright wrong feedback and now you’ve sent them down a goose chase.

      • rohansood15 a month ago

        This is where prompting and context is key - you need to keep the scope of the review limited and well-defined. And ideally, you want to validate the review with another LLM before passing it to the dev.

        Still won't be perfect, but you'll definitely get to a point where it's a net positive overall - especially with frontier models.

      • throwthrowuknow a month ago

        That happens with human review too and often serves as an opportunity to clarify your reasoning to both the reviewer and yourself. If the code is easily misunderstood then you should take a second look at it and do something to make it easier to understand. Sometimes that process even turns up a problem that isn’t a bug now but could become one later when the code is modified by someone in the future.

  • meiraleal a month ago

    I stand corrected: LLMs are great to block PRs by raising issues. A lack of issues should not be taken as a good PR tho.

  • datashaman a month ago

    We're trialing ellipsis.dev for exactly this, and it's pretty good most of the time.

SOLAR_FIELDS a month ago

A feature comparison to https://github.com/paul-gauthier/aider would be great.

Is this just a non interactive version of this kind of agent?

  • rohansood15 a month ago

    Aider is great, but the use case is different:

    1. You use Aider to complete a novel task you're actively working on. Patchwork completes repetitive tasks passively without bothering you. For e.g. updating a function v/s fixing linting errors.

    2. Aider is agentic, so it figures out how to do a task itself. This trades accuracy in favor of flexibility. With patchwork, you control exactly how the task is done by defining a patchflow. This limits the set of tasks to those that you have pre-defined but gives much higher accuracy for those tasks.

    While the demo shows CLI use, the ideal use case patchwork is as part of your CI or even a serverless deployment triggered via event webhooks. Hope this helps? :)

lifeisstillgood a month ago

Ok the video explains this way better - and it looks awesome.

Do you accept PRs yourself :-)

  • rohansood15 a month ago

    We do. We haven't done a very good job of listing good first issues, but please feel free to create and contribute.

danielhanchen a month ago

Oh this is really cool and great name! Will definitely try this out!

bsima a month ago

Yall know there’s a popular oss project called patchwork right https://patchwork.readthedocs.io/en/latest/