Our eyes, your supply chain.

Trust Open Source in One Click.

Meerkat assesses, monitors, and remediates software supply chain security risks and licensing violations in your environment. Whether you are developing software or simply using open source software (most third party apps silently embed it), Meerkat separates the good from the bad.

Why Meerkat Stands Out

Deep-Scope Vulnerability Scanning

Meerkat goes beyond a simple CVE lookup. It continuously cross-references every discovered package against known vulnerability databases and a live vulnerability intelligence feed, flagging known issues before they reach production.

Vendor & Third-Party Risk Approval

The platform embeds a full vendor-approval workflow — security scorecards, country/organization checks, maturity ratings, and governance reviews — so you can certify external suppliers once and enforce that approval across all your repositories.

Pre-Commit Artifact Control

Meerkat sits between your developers' toolchain and the internet, blocking outdated, insecure, or non-compliant artifacts before they are ever published to your Git host. It stops vulnerable libraries, licensing violations, or stale binaries from entering your codebase — a capability most artifact registries don't provide out of the box.

One Dashboard. Unlimited Visibility.

Meerkat – The Radar That Finds Every Package Dependency in Your Repository Universe.

Modern software projects pull in dozens — or hundreds — of third-party packages. When a vulnerability or malicious code is discovered in one of those libraries, every downstream repository that depends on it becomes exposed. Because the dependency graph is hidden inside each repository, security teams often spend days or weeks manually tracing which codebases are at risk, missing critical exposures and delaying remediation.

Recent high-profile supply-chain incidents (e.g., compromised TanStack npm packages and a self-replicating worm that infected 180+ libraries) show how quickly an untracked dependency can become a catastrophic attack vector.

Frequently Asked Questions

Your Git host's scanners run per-project and produce isolated reports. Meerkat aggregates the results across all groups, gives a searchable global view, and ties alerts directly to the projects that need attention.
Traditional SBOM tools generate a one-time snapshot per project. Meerkat continuously scans every repository, cross-references the live vulnerability threat feed, enforces policy via CI gates, and sends real-time alerts — all from a single interface.
Meerkat polls the vulnerability threat feed on a configurable schedule. When a new malicious package is detected, it is automatically added to the deny list and all affected project owners are notified immediately.
The CI agent is a single static binary that sends one HTTP request to the Meerkat server and receives a pass/fail response. Typical round-trip time is under one second and does not trigger a new scan — it reads the result from the most recent scan already in the database.
Yes. Meerkat's allow-list can be scoped to specific repository groups or individual projects. The CI agent checks each build against the active allow-list and fails the pipeline if an unapproved dependency is introduced.

Key Benefits

Instant, organisation-wide visibility
One dashboard shows every project's dependencies, versions and ecosystems across all your repository groups.
Real-time threat protection
The vulnerability threat feed auto-adds malicious packages to a deny list and surfaces new CVEs instantly.
Continuous, automated scanning
Nightly full scans plus webhook-triggered rescans keep the inventory always up to date.
Smart, configurable alerts
Email or chat notifications warn teams of policy violations, scan errors, or newly discovered malware.
Policy enforcement and reporting
Define allow-lists, enforce them via the CI agent, and generate clear, ecosystem-grouped reports.

Built for the Teams Responsible for What Ships.

In today's fast-moving development landscape, unmanaged third-party libraries are the weakest link in every software supply chain. Meerkat turns that hidden risk into actionable insight, giving security, compliance, and DevOps teams the tools they need to detect, prioritise and remediate vulnerable dependencies at scale.

Security operations
Quickly locate every repository affected by a newly disclosed CVE so remediation can be prioritised and coordinated across teams.
Compliance & audit
Enforce approved dependency allow-lists and generate SBOM-style reports that satisfy internal policies and regulatory requirements.
DevOps efficiency
Trigger automatic rescans from CI pipelines without slowing builds, giving developers immediate feedback on forbidden or vulnerable packages.
Risk management
Stay ahead of supply-chain attacks by automatically adding reported malicious packages to a deny list and alerting owners in real time.
Incident response
When an exploit is discovered, use the "Hunt" feature to pinpoint all projects using the compromised package and roll out fixes in minutes instead of days.

From Repo to Risk: Automated Scanning, Clear Reporting, Zero Guesswork.