Financial services firm fixed 100 critical security issues in one CI/CD run.

A global financial services company now fixes more than 100 critical security issues in a single CI/CD run across hundreds of Java services. Remediation that took weeks of coordination across teams now takes hours, with Moderne running inside the GitHub pipelines the company already uses.

100s
Java services
Java, Spring Boot, GitHub
Primary stack
Financial services
Industry
100+
Critical security issues fixed in a single CI/CD run
Weeks to hours
Security remediation across hundreds of services

When a CVE lands, the company’s teams now fix it without writing custom scripts.

Security updates used to be deprioritized because of the manual overhead. They now run as part of an automated process. Teams validate each fix in staging and push it across production without slowing delivery. Changes are checked across hundreds of repositories in parallel, which keeps decentralized teams and legacy systems consistent with each other.

One remediation process now covers PCI, SOX and the company’s internal security domains. The core services are also architected for Java 21.

Moderne let us take a process that used to involve weeks of coordination and manual scripting, and replace it with something we could kick off in a few clicks.
Engineering Team Lead, Financial services company

Recipes now carry the company’s security fixes through its existing GitHub pipelines.

The platform engineering team had used OpenRewrite before, but now needed something that could run changes safely across dozens of teams at once.

The team connected Moderne to GitHub and the company’s CI/CD pipelines, so developers review and ship the automated changes with the tools they already use.

Manual and agent-driven edits can differ from one repository to the next, so each has to be checked on its own. A recipe gives every repository the same change, so it can be reviewed as one change instead of hundreds. And when a coding agent applies a fix, it calls the same recipes through Moderne, so reviewers see the same change whether a person or an agent made it.

For a regulated company, being able to show what changed matters more than the time saved, because an auditor needs proof that every fix was applied.

Four kinds of work now run this way:

  • Upgrading vulnerable libraries and cleaning up the risky patterns around them
  • Migrating to Spring Boot 3.0 and Java 17 without a custom script for each team
  • Enforcing secure defaults through the company’s own internal recipes
  • Pushing the resulting changes through GitHub pipelines for teams to validate and deploy

The company’s security standard now applies the same way in every team.

The company operates in a regulated, security-sensitive environment, with hundreds of Java services in GitHub-hosted monorepos running inconsistent versions of frameworks like Spring Boot over complex dependency trees. Its developers and DevSecOps practices were already strong, and static analysis and vulnerability scanning surfaced the alerts.

Upgrading the packages, removing deprecated methods and verifying each fix still fell to developers, one service at a time. Each team remediated a little differently, which duplicated effort and produced inconsistent results. Security fixes competed with delivery for the same hours and lost often enough that they piled up.

The company is looking to deepen the integration into its DevSecOps toolchain, so every change is traceable and auditable against internal policy.

We already had great developers and strong processes. Moderne just gave us a way to scale that, automating the things we used to do by hand and helping us move faster with more confidence.
Engineering Leader, Financial services company

See deterministic, estate-wide code change on your own repositories.