Introducing the Verifi CLI: the safe fix for your vulnerable dependencies
Verifi starts as one open-source CLI. Point it at a project and it works out the safe fix for each vulnerable dependency your code actually uses, tells you how sure it is and why, and is honest about the limits.
Read more

Decide, Then Fix: The Only Two Steps That Matter
Detection was never the hard part. Findings are a commodity now, they come from anywhere. The gap between a finding and a merged fix is where risk lives, and closing it is the whole product.

Adversaries Are Publishing at Scale. Speed Is Now the Only Defence.
A corpus of roughly 1,000 malicious packages impersonating TanStack libraries surfaced recently via jsDelivr telemetry. It is not an anomaly. It is the new baseline. The only meaningful response is to act faster than the blast radius can spread.

H2 2026: Packages Are the New Phishing Email, and Your Secrets Are the Target
Axios. LiteLLM. TeamPCP. Anthropic's AI adversary report. The first half of 2026 has given us enough signal to make a clear prediction: the second half will be worse. Malicious packages are not a supply chain problem any more. They are a credential theft problem. And most organisations are not set up to respond fast enough.

Mini Shai-Hulud: The Self-Replicating npm Worm That Should Change How You Think About Dependencies
The fourth campaign in the Shai-Hulud series has arrived. Mini Shai-Hulud targets SAP packages, TanStack and agentic AI libraries with a self-propagating worm that steals credentials, injects malicious code and spreads across your entire CI/CD estate before your scanner has filed a ticket.

AI Coding Is Creating Dependency Sprawl
AI coding assistants are transforming how software is built, but they are also quietly flooding enterprise codebases with unvetted dependencies at a scale security teams were never prepared for.

Why Dependency Hygiene Is the New AppSec Backlog
For years, application security teams have wrestled with vulnerability backlogs: thousands of findings, prioritised by severity, worked down slowly by engineering teams. Dependency hygiene is becoming the same problem, at greater scale.

From Detection to Orchestration in Software Supply Chain Security
The software supply chain security market has spent a decade getting very good at detection. The next decade belongs to orchestration: the operational layer that takes detection signals and turns them into controlled, verified remediation.
See how Verifi puts this into practice
The Verifi CLI turns this thinking into policy decisions and automated fixes, right in your build.