Improvements
Autofix
An Autofix is an Enji Guard improvement run that selects one bounded candidate, keeps a provider issue as its baseline artifact, and may open one verified pull or merge request for review.
What it means
An Autofix is one improvement run in Enji Guard. It begins from current audit context, or from a narrow candidate the runbook finds itself, selects one bounded change instead of a broad cleanup, and rechecks it against the repository as it is now.
The provider issue is the baseline artifact of a supported Autofix job. If the write toggle allows it and the change is current, bounded, reversible, and verifiable, the run may also open one pull or merge request for review.
An Autofix is none of the word’s other meanings:
- Linter autofix. ESLint’s
--fixand Semgrep’s--autofixwrite fixes straight into the files. - Copilot Autofix. GitHub generates a single suggested fix for a code scanning alert, proposed code changes that the developer reviews and accepts.
- Dependency bots and cloud auto-remediation. Dependabot raises a pull request when it finds an outdated dependency; Automated Security Response on AWS runs predefined playbooks against Security Hub findings. Both act on dependency or cloud state, not application code.
How it works
- Revalidate. The run rechecks the candidate, repository identity, current commit, provider state, and duplicate work.
- Apply the write mode. With Open a pull request with the fix off, the run creates or reuses one issue and edits no files; with it on, it may also open one review request.
- Verify. It records baseline checks, targeted checks after the edit, and its limitations.
- Finish with one outcome. Issue only; issue plus a verified pull or merge request; verification failed; needs human review; blocked; already resolved; or no action.
The toggle allows the bounded path; a run can still end with no code.
Where it appears in Enji Guard
- Autofix labels the fix block on the repository dashboard and the live run kind; a finding on the audit page offers Select autofix.
- Recurring fixes is the automation setting that schedules fixes on a cadence. Its note reads: “Autofix does not guarantee a Pull Request: sometimes creating changes is unsafe or not worth doing. An Issue with the result will always be created.”
- Autofix report and Autofix history hold a run’s result and earlier runs for the audit group.
Scheduled runs charge credits automatically.
How Enji Guard helps
The repository dashboard states the scope: the agent fixes one critical problem per run, so each diff stays easy to review and roll back.
A merged pull request is not proof that health changed. Rerun the affected audit; the new report shows whether the finding is gone and which area now sits lowest. The project moves toward the green zone on that rerun, not on the merge.
Enji Guard does not push to the default branch and does not merge; which decisions stay with the team is covered under human approval.
Enji Guard