<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/8d692ca5cf12407b9b216301a7a7344b&quot; frameborder=&quot;0&quot; width=&quot;1108&quot; height=&quot;831&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>831</height><width>1108</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>831</thumbnail_height><thumbnail_width>1108</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/8d692ca5cf12407b9b216301a7a7344b-990b9387f0ff73fb.gif</thumbnail_url><duration>170.935</duration><title>Jingkong Secures Code With Verified Fixes</title><description>This Loom presents Jingkong, the Hexon product, which automatically guards against newly exploited security bugs by matching vulnerable versions, checking reachability, and shipping verified fixes. It runs four steps: match the installed version against advisory ranges, expose only when code calls vulnerable functions checked via a semgrep rule, suppress noise when the function is not reachable, and upgrade to the newest package version outside every advisory. The agent then forces transitive copies using npm overrides, runs tests, opens a PR, and stores guardrails so the same bug cannot return. A historical dashboard shows aggregated vulnerability matches and detailed log events, and a real-life run demonstrates PR generation and guardrail effectiveness, including a suppressed count.</description></oembed>