Red Hat announced jointly-engineered, integrated and supported images for Red Hat Enterprise Linux across Amazon Web Services (AWS), Google Cloud and Microsoft Azure.
Kusari raised $8 million through combined investments in Pre-Seed and Seed Round funding.
The Seed Round was led by J2 Ventures and co-led by Glasswing Ventures with participation from Unusual Ventures, which previously invested $2 million in Pre-Seed funding.
Kusari was established in June 2022 to address the lack of transparency within the software supply chain and development lifecycle, which can lead to costly security vulnerabilities. Cybersecurity Ventures recently reported that the global annual cost of software supply chain attacks to businesses will reach $60 billion in 2025, and is expected to increase to $138 billion by 2031. Transparency into the software supply chain will allow organizations to identify potential weak points and resolve issues faster, helping them maintain trust with partners and minimize risk.
Kusari’s founders, Tim Miller, Michael Lieberman, and Parth Patel, are seasoned navigators of software supply chains with experience leading supply chain security and cloud engineering at Citi, Mitsubishi UFJ Financial Group (MUFG), Bridgewater Associates, and Raytheon. They have personally dealt with the complicated problem of securing software delivery while enabling developer productivity within highly regulated, security-conscious environments. The founding team provides technical leadership and guidance in the Open Source Security Foundation (OpenSSF), which brings together the industry's most important open source security initiatives and the individuals and companies that support them. The Kusari founders also have created many open source projects, including Graph for Understanding Artifact Composition (GUAC), which is supported by industry-leading financial services and technology companies, including Yahoo!, Guidewire, Google, Microsoft, Red Hat, and ClearAlpha Technologies.
Open source libraries comprise the majority of most software written today. Each relies on other libraries, creating a complicated tree of dependencies. Securing a software supply chain starts with understanding how each piece is put together. It can be deceivingly difficult for an organization to understand what this looks like, as modern software development practices work to hide this complexity in favor of easy development.
Kusari introduced and achieved market validation for GUAC in 2023 to address this specific problem. GUAC is an open source tool that addresses the lack of transparency by organizing software supply chain information, like software bills of materials (SBOMs), into a knowledge graph. The project has a diverse community of 50 contributors and has garnered 1.1k GitHub stars.
Kusari will use the funding to accelerate and build on its continued momentum in developing software supply chain security solutions that enable organizations to achieve actionable insights, reduce incident response costs, and relieve the burden on security and developer teams.
“Kusari’s blend of team, technology, and significant adoption, even at this early stage, position them to be a market leader. Our initial indication from government agencies for what they’re building revealed a massive commercial market. GUAC’s potential cannot be overstated,” said Jonathan Bronson, Ph.D., co-founder and Managing Partner of J2 Ventures.
"Code breaches are increasingly becoming a top priority for Chief Information Security Officers,” said Kleida Martiro, Partner, Glasswing Ventures. “In an era where software supply chain attacks are on the rise, the demand for stringent security measures has never been more critical. At the helm of Kusari, a team of seasoned industry veterans, including Tim, Michael, and Parth, are steering the company toward new heights. We are immensely proud of our investment in Kusari. Their unparalleled knowledge and innovative approach position them at the cutting edge, as they lead the charge in defining and delivering groundbreaking security solutions in this vital and evolving space.”
“Identifying where vulnerabilities lie in your software supply chain is complex and time-consuming. With the ever-increasing number of vulnerable packages discovered each year, organizations need a single source of truth about their code,” said Tim Miller, co-founder and CEO of Kusari. “Kusari will be that source of end-to-end transparency and will bring about insights for users to drive more secure outcomes for their organizations. Our focus is on helping users solve their very real security problems.”
Industry News
Komodor announced the integration of the Komodor platform with Internal Developer Portals (IDPs), starting with built-in support for Backstage and Port.
Operant AI announced Woodpecker, an open-source, automated red teaming engine, that will make advanced security testing accessible to organizations of all sizes.
As part of Summer '25 Edition, Shopify is rolling out new tools and features designed specifically for developers.
Lenses.io announced the release of a suite of AI agents that can radically improve developer productivity.
Google unveiled a significant wave of advancements designed to supercharge how developers build and scale AI applications – from early-stage experimentation right through to large-scale deployment.
Red Hat announced Red Hat Advanced Developer Suite, a new addition to Red Hat OpenShift, the hybrid cloud application platform powered by Kubernetes, designed to improve developer productivity and application security with enhancements to speed the adoption of Red Hat AI technologies.
Perforce Software announced Perforce Intelligence, a blueprint to embed AI across its product lines and connect its AI with platforms and tools across the DevOps lifecycle.
CloudBees announced CloudBees Unify, a strategic leap forward in how enterprises manage software delivery at scale, shifting from offering standalone DevOps tools to delivering a comprehensive, modular solution for today’s most complex, hybrid software environments.
Azul and JetBrains announced a strategic technical collaboration to enhance the runtime performance and scalability of web and server-side Kotlin applications.
Docker, Inc.® announced Docker Hardened Images (DHI), a curated catalog of security-hardened, enterprise-grade container images designed to meet today’s toughest software supply chain challenges.
GitHub announced that GitHub Copilot now includes an asynchronous coding agent, embedded directly in GitHub and accessible from VS Code—creating a powerful Agentic DevOps loop across coding environments.
Red Hat announced its integration with the newly announced NVIDIA Enterprise AI Factory validated design, helping to power a new wave of agentic AI innovation.
JFrog announced the integration of its foundational DevSecOps tools with the NVIDIA Enterprise AI Factory validated design.
GitLab announced the launch of GitLab 18, including AI capabilities natively integrated into the platform and major new innovations across core DevOps, and security and compliance workflows that are available now, with further enhancements planned throughout the year.