Kusari Inspector Released
June 17, 2025

Kusari unveiled Kusari Inspector, an artificial intelligence (AI)-based pull request security tool that brings cutting-edge security risk analysis directly into developers’ daily workflows.

In Kusari Inspector, Kusari has brought together a powerful combination of industry standards, AI, and dependency graph analysis, to help organizations detect software supply chain risks early during the pull request process, and address them before code integration. The tool finds security weaknesses and supply chain risks in order to maintain secure development throughout every stage.

“Kusari Inspector puts robust security insights right where developers need them: in their pull requests. The recommendations come from Kusari’s analysis of the full dependency graph, including security practices and code provenance, so the result is always actionable — there’s no worry about ‘AI slop.’ By catching vulnerabilities and risky dependencies early, teams can move faster and ship more secure code,” said Tim Miller, CEO and Co-Founder at Kusari.

In addition to core supply chain analysis, Kusari Inspector introduces advanced safeguards and interactive features to further empower developer security.

Key Features & Benefits

- Pull Request Inspection & Analysis: Receive instant, context-rich, annotated security reports with inline explanations on every new or updated pull request, saving time and reducing back-and-forth with security teams.

- Safe to Merge: Clear go/no-go guidance, remediation suggestions, and step-by-step instructions to mitigate risks. Flags exposed credentials, sensitive secrets, workflow misconfigurations; blocks typosquatted or maliciously named dependencies and prohibited licenses; enforces rules and policies across the organization.

- Prioritized Risk Assessments & Reduced Alert Noise: Identify and rank risky, low-trust, or vulnerable dependencies—direct and transitive—based on industry trusted data sources (CVSS, EPSS, Known Exploited Vulnerabilities) early in development and reduce noise by accounting for unexploitable vulnerabilities.

- Adaptive AI Model with Interactive Guidance: Delivers precise safe to merge guidance through deep code analysis, continuously learning from your codebase and preferences. Developers can chat with AI to clarify findings, customize recommendations, and set security standards.

- Automated SBOM Generation: Automatically generate and collect source SBOM data for all connected projects and repositories.

“Installing Kusari Inspector in your code repository takes just a few minutes, and then your vulnerabilities, risks, and license issues are immediately detected and flagged within your pull requests. This empowers developers to address security concerns early—eliminating the need for lengthy and iterative security reviews. With Kusari Inspector, a simple three-minute fix can prevent weeks of delay and frustration, allowing developers to stay focused on building great software,” shared Michael Lieberman, CTO and Co-Founder at Kusari.

Kusari Inspector is now available for GitHub repositories .

Share this

Industry News

June 26, 2025

Backslash introduced a new, free resource for vibe coders, developers and security teams - the Backslash MCP Server Security Hub.

June 26, 2025

Google's Gemma 3n is the latest member of Google's family of open models. Google is announcing that Gemma 3n is now fully available for developers with the full feature set including supporting image, audio, video and text.

June 26, 2025

Google announced that Imagen 4, its latest text-to-image model, is now available in paid preview in Google AI Studio and the Gemini API.

June 26, 2025

Payara announced the launch of Payara Qube, a fully automated, zero-maintenance platform designed to revolutionize enterprise Java deployment.

June 25, 2025

Google released its new AI-first Colab to all users, following a successful early access period that had a very positive response from the developer community.

June 25, 2025

Salesforce announced new MuleSoft AI capabilities that enable organizations to build a foundation for secure, scalable AI agent orchestration.

June 25, 2025

Harness announced the General Availability (GA) of Harness AI Test Automation – an AI-native, end-to-end test automation solution, that's fully integrated across the entire CI/CD pipeline, built to meet the speed, scale, and resilience demanded by modern DevOps.

With AI Test Automation, Harness is transforming the software delivery landscape by eliminating the bottlenecks of manual and brittle testing and empowering teams to deliver quality software faster than ever before.

June 25, 2025

Wunderkind announced the release of Build with Wunderkind — an API-first integration suite designed to meet brands and developers where they are.

June 25, 2025

Jitterbit announced the global expansion of its partner program and new Jitterbit University partner curricula.

June 24, 2025

Tricentis unveiled two innovations that aim to redefine the future of software testing for the enterprise.

June 24, 2025

Snyk announced the acquisition of Invariant Labs, an AI security research firm and early pioneer in developing safeguards against emerging AI threats.

June 24, 2025

ActiveState expanded support of secure open source to include free and customized low-to-no vulnerability containers that facilitate modern software development.

June 24, 2025

Pythagora launched an all-in-one AI development platform that enables users to build and deploy full-stack applications from a single prompt.

June 24, 2025

Cloudflare announced that Containers is in public beta.

June 23, 2025

The Linux Foundation, the nonprofit organization enabling mass innovation through open source, announced the launch of the Agent2Agent (A2A) project, an open protocol created by Google for secure agent-to-agent communication and collaboration.