Find the vulnerable software on your fleet, and patch it automatically.
Every Mac is running open source someone installed off the internet, and some of it is out of date and exploitable. Vulnerability Patching shows you exactly which packages are vulnerable across every device, and fixes them for you.
- $5 / device / month upgrade to the free Team plan
- Included with Business and Enterprise plans
- Included with Governance
The problem
Your free Team plan already shows you everything your team has installed. The harder question is which of it is an issue. A package that was safe when it was installed is a CVE waiting to happen six months later, sitting unpatched on a laptop nobody's looking at.
supply chain attacks in 2025
What you get
Every vulnerable package, in one view.
Workbrew checks the software installed across your fleet against known vulnerabilities and scores each one by severity. You see which devices are affected and how badly, without touching a single machine.
Patch by severity, automatically.
Set a threshold once — say critical and above — and Workbrew keeps everything at or beyond it patched across the whole fleet. From then on it runs on its own, so a device that picks up a vulnerable package is brought back into line at its next check-in.
More than Homebrew.
You already see npm, macOS apps, and extensions across every plan. Patching remediates your Homebrew formulae and casks and your npm packages today, with VS Code extensions on the way.
How it works
Each device reports the software and versions it's running. Workbrew checks that against the vulnerability database, scores every match, and compares it to the severity threshold you set.
Anything at or above the line gets patched. Anything below it still shows up in your vulnerabilities view, so if you decide it matters later — lower the threshold and it's covered too.
Frequently Asked Questions
Just the vulnerable items. Vulnerability Patching remediates packages with known vulnerabilities at the severity you choose. Keeping every package current for its own sake, vulnerable or not, is a separate capability on Business and Enterprise.
Homebrew formulae and casks and your npm packages today, with VS Code extensions on the way. Visibility into what's installed already spans Homebrew, npm, macOS apps, and extensions on every plan.
Patching works by severity range rather than one vulnerability at a time — you set the bar, and Workbrew keeps everything above it fixed across the fleet. It's built to stay ahead of vulnerabilities on its own, rather than have you chase them one by one.
Rarely. Most people keep installing and working exactly as before, in the terminal or the Workbrew app. Patching happens quietly at each device's next check-in. Because it upgrades software in place, it can occasionally interrupt something that's actively running, the way any update can — a small price for a fleet that stays clear of known vulnerabilities.
It's an upgrade you switch on inside the free Team plan: $5 per device per month, or $4.50 with annual billing, covering every device in your workspace. Business and Enterprise include it, so there's nothing extra to buy there. And if you later add Governance, its $10 price includes Vulnerability Patching — you never pay for both.
Deploy Workbrew free
Turn on Vulnerability Patching when you're ready.