Dependency update and CVE fix factory station
Platform and security teams can package one repetitive maintenance class as a factory station before widening agent use. A good starting point is dependency updates or CVE fixes across a known repo set. Each job should include the advisory or ticket, target repos, allowed commands, non-goals, reproduction steps, validation checks, no-op rules, required evidence, and a fixed output state such as PR_READY, NO_OP, ESCALATE, or RETRYABLE_FAILURE.
The useful build is the wrapper around the coding agent: intake, classification, isolated workspace setup, implementation, tests, evidence capture, retry limit, and review queue. The first pilot can run on 10 repos and count how many jobs produce reviewable PRs, justified no-ops, or escalations. The safety check should live in tests, logs, screenshots, traces, ADR checks, or other reviewer-visible evidence, since the agent’s explanation is not enough for maintenance work that touches production code.