VerifiVerifi

Verifi

From finding to fixed.

Findings come from anywhere. Verifi decides what matters by policy and drives the fix end to end, opening the PR, gating the build, blocking the install.

CoveragenpmnpmsoonMavensoonPyPIsoonGoGosoonMore →

Findings from anywhere

Verifi's own resolve and match, or a scanner, feed, or runtime signal you already have.

Resolve the tree

Every dependency in your software, direct and transitive, built in.

Tagged and sourced

Vulnerable, end-of-life, or malicious, each finding traceable to where it came from.

What Verifi does with a finding

01

Fix it in your repo

For anything with a known fix, Verifi bumps the version, direct or transitive, or swaps the package out and opens the pull request. The one step that actually moves the number.

Decide, then fix
02

Gate the build

No fix available yet? Verifi fails the build on a policy violation, so nothing that breaks your policy ships. One policy, two modes: fix what it can, gate the rest.

From detection to orchestration
03

Block at the edge

Roadmap

Stop a malicious or disallowed package at the registry firewall, before a developer or CI ever installs it.

Adversaries publishing at scale
04

Contain across the estate

Roadmap

When something already landed, Verifi maps the blast radius and drives containment, purging caches, pulling the package, and opening fix PRs across every affected repo, as one workflow.

Inside Mini Shai-Hulud

Questions, answered

In your terminal and in your CI. It's a CLI, so it runs locally on your machine and as a step in your build pipeline: GitHub Actions, GitLab CI, Jenkins, or anything that can run a shell command.

Yes. The CLI is open source and free to use. It lives on GitHub, so you can read exactly what it does, run it, and contribute.

Just your software. Point Verifi at it and it maps out every dependency, with no account, no agent, and nothing to install into your code.

npm and Maven to start, with more ecosystems on the way. It maps every dependency in your software, both direct and transitive.

No. Verifi pulls intelligence to you, not your code to us. Scanning and fixing happen locally; your source never leaves your environment.

For anything with a known fix, it bumps the version, direct or transitive, or replaces the package and opens a pull request. Findings without a fix path gate the build instead.

Built for teams
who ship fast

Get the developer newsletter

Supply-chain threats, new IOCs, and how-tos. Delivered monthly to your inbox.

You can unsubscribe at any time.