For open source and solo developers

Review the code you didn't write.

Inspector reviews each pull request and the dependencies it pulls in, several layers down, and comments with what it found and how to fix it. Free for the repositories you own and for OpenSSF and CNCF projects.

The code you wrote is solid.

Your project also ships every package it depends on, and every package those depend on.

96% of vulnerabilities sit at least two layers below the dependency a developer changed.

That's from J.P. Morgan's Patchmageddon report. Inspector follows the graph down and reports what a change moved.

In their words

Developers and maintainers using Kusari Inspector.

"
I like seeing it identify new dependencies in my changes that I wasn't otherwise tracking closely and I appreciate some of the signal it surfaces to me (like licenses, inactivity, etc.). I suspect it'll be additionally useful if/when I do more work on zizmor's VS Code extension, since I'm not a JS expert and will be relying on tooling more to help me determine my dependency posture/exposure.
William WoodruffZizmor maintainer
"
I have to say, I used Claude to submit a PR to go-witness. Inspector found an issue (it wasn't generated by Claude but, Claude didn't fix it either). I just asked Claude to fix the issue Inspector found... and it did it.
John Kjellin-toto/Witness maintainer
"
Shout out to Kusari Inspector and its _very_ detailed report on pull requests. Keep it up!
Adolfo Garcia VeytiaFounder at Carabiner Systems and Kubernetes SIG Release Technical Lead
"
If you use GitHub and you do not have this for your PR review process, you are just doing it wrong, regardless of your risk appetite. Kusari Inspector gives clear, contextual security checks—right in your pull requests, boom!
Joseph SteinPrincipal Data Architect, SS&C Technologies
"
Kudos! I have been using Kusari Inspector for some of my projects and it's been awesome!
Anoop GopalakrishnanVice President of Engineering at Guidewire Software
"
Kusari Inspector is a really cool way of applying AI to solving a serious security problem. How many of you are reviewing the dependency update PRs? Let the LLM do the work for you.
Mihai MaruseacStaff Software Engineer, Google

See what a version bump changes.

A dependency update shows a reviewer one changed version number. Underneath it, the bump can move transitive packages several layers down. Inspector reviews the pull request and reports what changed below the manifest.

What the diff shows
  • One version number
  • —
  • —
  • —
  • —
What Inspector reports
  • New dependencies, several layers down
  • Known vulnerabilities, with severity and likelihood of exploit
  • License changes
  • Packages that have gone inactive
  • The version change that fixes a finding at its root
Wherever you ship

Review right in your workflow.

Inspector comments on the pull request, where you already review changes.

GitHub App

Inspector, native to your pull requests

Install it on your repositories and every pull request gets a review: new dependencies, vulnerabilities, licenses, and package health, posted as a comment.

Install on GitHub
GitLab and CLI

The same review on GitLab and your laptop

Inspector reviews GitLab merge requests natively. The Kusari CLI runs the same analysis locally before you open a pull request, and CI templates add it to other pipelines.

See the setup guides
For maintainers

Your project is someone else's dependency.

Every release you publish lands in other people's builds, including at companies that have to account for every package they ship. Inspector flags what a change pulls in before it goes out in a release, so your users don't inherit it.

Who builds it

Built by the people who maintain SLSA.

Mike Lieberman maintains SLSA. The team built GUAC with Google, and it now lives under the OpenSSF. Kusari engineers also maintain in-toto projects.

See our open source work

Software supply chain insights.

All resources
FAQ

What maintainers ask first.

What does Inspector cost for open source and solo developers?

Nothing. Inspector is free for the repositories you own, and for any project under the OpenSSF or the CNCF. Agentic Analysis, SBOM generation, and the Kusari Platform are part of paid plans. If you want Inspector across your employer's repositories, team pricing starts at $25 per developer per month.

Does my source code leave my repository?

Inspector analyzes the changed files and the dependency graph, and does not store your code in any form. Once the analysis finishes, the input is deleted. Data is encrypted in transit and at rest, and Kusari is SOC 2 Type II compliant.

What languages and ecosystems does Inspector cover?

Go (go.mod, go.sum), Node.js (package-lock.json, yarn.lock), Python (requirements.txt, poetry.lock, Pipfile.lock, uv.lock), Java (pom.xml, gradle.lockfile), .NET (.csproj, .vbproj, .fsproj), Ruby (Gemfile.lock), and Rust (Cargo.lock).

Inspector also reads HashiCorp Configuration Language, which covers Terraform and OpenTofu, along with Dockerfiles, GitHub workflow files, and Helm charts.

Does Inspector review Dependabot pull requests?

Yes. A Dependabot pull request gets the same review as any other change. The diff shows a version number, and Inspector reports what moved underneath it.

Get started

Try it on a public repo.

Install the GitHub App on a public repo and your next pull request gets a review. No sales call required.