VerifiVerifi
Product

Introducing the Verifi CLI: the safe fix for your vulnerable dependencies

Verifi starts as one open-source CLI. Point it at a project and it works out the safe fix for each vulnerable dependency your code actually uses, tells you how sure it is and why, and is honest about the limits.

Read more
Opinion

Decide, Then Fix: The Only Two Steps That Matter

Detection was never the hard part. Findings are a commodity now, they come from anywhere. The gap between a finding and a merged fix is where risk lives, and closing it is the whole product.

Sim Chiwanza · 9 Jul 2026 · 4 min read
Opinion

Adversaries Are Publishing at Scale. Speed Is Now the Only Defence.

A corpus of roughly 1,000 malicious packages impersonating TanStack libraries surfaced recently via jsDelivr telemetry. It is not an anomaly. It is the new baseline. The only meaningful response is to act faster than the blast radius can spread.

Sim Chiwanza · 20 May 2026 · 5 min read
Opinion

H2 2026: Packages Are the New Phishing Email, and Your Secrets Are the Target

Axios. LiteLLM. TeamPCP. Anthropic's AI adversary report. The first half of 2026 has given us enough signal to make a clear prediction: the second half will be worse. Malicious packages are not a supply chain problem any more. They are a credential theft problem. And most organisations are not set up to respond fast enough.

Sim Chiwanza · 20 May 2026 · 6 min read
Opinion

Mini Shai-Hulud: The Self-Replicating npm Worm That Should Change How You Think About Dependencies

The fourth campaign in the Shai-Hulud series has arrived. Mini Shai-Hulud targets SAP packages, TanStack and agentic AI libraries with a self-propagating worm that steals credentials, injects malicious code and spreads across your entire CI/CD estate before your scanner has filed a ticket.

Verifi Research Labs · 20 May 2026 · 7 min read
Opinion

AI Coding Is Creating Dependency Sprawl

AI coding assistants are transforming how software is built, but they are also quietly flooding enterprise codebases with unvetted dependencies at a scale security teams were never prepared for.

Verifi Research Labs · 2 May 2026 · 6 min read
Opinion

Why Dependency Hygiene Is the New AppSec Backlog

For years, application security teams have wrestled with vulnerability backlogs: thousands of findings, prioritised by severity, worked down slowly by engineering teams. Dependency hygiene is becoming the same problem, at greater scale.

Verifi Research Labs · 19 Apr 2026 · 5 min read
Opinion

From Detection to Orchestration in Software Supply Chain Security

The software supply chain security market has spent a decade getting very good at detection. The next decade belongs to orchestration: the operational layer that takes detection signals and turns them into controlled, verified remediation.

Verifi Research Labs · 5 Apr 2026 · 7 min read

See how Verifi puts this into practice

The Verifi CLI turns this thinking into policy decisions and automated fixes, right in your build.