Vulnerability Patching

Find the vulnerable software on your fleet, and patch it automatically.

Every Mac is running open source someone installed off the internet, and some of it is out of date and exploitable. Vulnerability Patching shows you exactly which packages are vulnerable across every device, and fixes them for you.

  • $5 / device / month upgrade to the free Team plan
  • Included with Business and Enterprise plans
  • Included with Governance

The problem

Your free Team plan already shows you everything your team has installed. The harder question is which of it is an issue. A package that was safe when it was installed is a CVE waiting to happen six months later, sitting unpatched on a laptop nobody's looking at.

73%Rise in open source
supply chain attacks in 2025

What you get

Every vulnerable package, in one view.

Workbrew checks the software installed across your fleet against known vulnerabilities and scores each one by severity. You see which devices are affected and how badly, without touching a single machine.

Patch by severity, automatically.

Set a threshold once — say critical and above — and Workbrew keeps everything at or beyond it patched across the whole fleet. From then on it runs on its own, so a device that picks up a vulnerable package is brought back into line at its next check-in.

More than Homebrew.

You already see npm, macOS apps, and extensions across every plan. Patching remediates your Homebrew formulae and casks and your npm packages today, with VS Code extensions on the way.

How it works

Each device reports the software and versions it's running. Workbrew checks that against the vulnerability database, scores every match, and compares it to the severity threshold you set.

Anything at or above the line gets patched. Anything below it still shows up in your vulnerabilities view, so if you decide it matters later — lower the threshold and it's covered too.

Frequently Asked Questions

Deploy Workbrew free

Turn on Vulnerability Patching when you're ready.