PatchHolmes: Agentic Patch Retrieval via Listwise Selection
PatchHolmes uses a listwise agent loop to pick vulnerability-fixing commits from a ranked candidate set.
The paper says many CVEs in major advisory databases still lack patch links, making retrieval a bottleneck for vulnerability workflows. PatchHolmes first builds a hybrid candidate list, then has an agent inspect the top 100 commits together and selectively open only 3 to 10 before choosing one. On GitHubAD, it reports Recall@1 gains over Favia and IRCoT, and the authors attribute the lift to the listwise inspection loop rather than model swaps. The system is described as running on a frozen open-weight model over a local Git repository, without fine-tuning or external search APIs. HF Daily Papers' note
The paper says many CVEs in major advisory databases still lack patch links, making retrieval a bottleneck for vulnerability workflows. PatchHolmes first builds a hybrid candidate list, then has an agent inspect the top 100 commits together and selectively open only 3 to 10 before choosing one. On GitHubAD, it reports Recall@1 gains over Favia and IRCoT, and the authors attribute the lift to the listwise inspection loop rather than model swaps. The system is described as running on a frozen open-weight model over a local Git repository, without fine-tuning or external search APIs. HF Daily Papers' note
score 4