Inspector, native to your pull requests
Install it on your repositories and every pull request gets a review: new dependencies, vulnerabilities, licenses, and package health, posted as a comment.
Install on GitHubInspector reviews each pull request and the dependencies it pulls in, several layers down, and comments with what it found and how to fix it. Free for the repositories you own and for OpenSSF and CNCF projects.
Your project also ships every package it depends on, and every package those depend on.
That's from J.P. Morgan's Patchmageddon report. Inspector follows the graph down and reports what a change moved.
I like seeing it identify new dependencies in my changes that I wasn't otherwise tracking closely and I appreciate some of the signal it surfaces to me (like licenses, inactivity, etc.). I suspect it'll be additionally useful if/when I do more work on zizmor's VS Code extension, since I'm not a JS expert and will be relying on tooling more to help me determine my dependency posture/exposure.
I have to say, I used Claude to submit a PR to go-witness. Inspector found an issue (it wasn't generated by Claude but, Claude didn't fix it either). I just asked Claude to fix the issue Inspector found... and it did it.
Shout out to Kusari Inspector and its _very_ detailed report on pull requests. Keep it up!
If you use GitHub and you do not have this for your PR review process, you are just doing it wrong, regardless of your risk appetite. Kusari Inspector gives clear, contextual security checks—right in your pull requests, boom!
Kudos! I have been using Kusari Inspector for some of my projects and it's been awesome!
Kusari Inspector is a really cool way of applying AI to solving a serious security problem. How many of you are reviewing the dependency update PRs? Let the LLM do the work for you.
A dependency update shows a reviewer one changed version number. Underneath it, the bump can move transitive packages several layers down. Inspector reviews the pull request and reports what changed below the manifest.
Inspector comments on the pull request, where you already review changes.
Install it on your repositories and every pull request gets a review: new dependencies, vulnerabilities, licenses, and package health, posted as a comment.
Install on GitHubInspector reviews GitLab merge requests natively. The Kusari CLI runs the same analysis locally before you open a pull request, and CI templates add it to other pipelines.
See the setup guidesEvery release you publish lands in other people's builds, including at companies that have to account for every package they ship. Inspector flags what a change pulls in before it goes out in a release, so your users don't inherit it.
Mike Lieberman maintains SLSA. The team built GUAC with Google, and it now lives under the OpenSSF. Kusari engineers also maintain in-toto projects.
See our open source workGet immediate software supply chain security insights right in your pull request or IDE.
Watch nowThe pull request workflow might seem unnecessary for projects with one developer, but it offers security, testing, and feedback benefits.
Read nowSecure development starts with developers: bring forth the code masters
Read nowNothing. Inspector is free for the repositories you own, and for any project under the OpenSSF or the CNCF. Agentic Analysis, SBOM generation, and the Kusari Platform are part of paid plans. If you want Inspector across your employer's repositories, team pricing starts at $25 per developer per month.
Inspector analyzes the changed files and the dependency graph, and does not store your code in any form. Once the analysis finishes, the input is deleted. Data is encrypted in transit and at rest, and Kusari is SOC 2 Type II compliant.
Go (go.mod, go.sum), Node.js (package-lock.json, yarn.lock), Python (requirements.txt, poetry.lock, Pipfile.lock, uv.lock), Java (pom.xml, gradle.lockfile), .NET (.csproj, .vbproj, .fsproj), Ruby (Gemfile.lock), and Rust (Cargo.lock).
Inspector also reads HashiCorp Configuration Language, which covers Terraform and OpenTofu, along with Dockerfiles, GitHub workflow files, and Helm charts.
Yes. A Dependabot pull request gets the same review as any other change. The diff shows a version number, and Inspector reports what moved underneath it.
Install the GitHub App on a public repo and your next pull request gets a review. No sales call required.