Meterian’s cover photo
Meterian

Meterian

Computer and Network Security

London, Greater London 1,149 followers

Continuously securing essential components in software apps

About us

Meterian secures your software supply chain by detecting and fixing open source vulnerabilities before they impact your business. Over 90% of software code today relies on open source libraries. But with that speed comes silent risk—from unpatched CVEs to license violations and supply chain exploits. Meterian’s platform delivers continuous, automated Software Composition Analysis (SCA) to help development, security, and legal teams gain instant visibility into open source risks. With zero-fuss integration into CI/CD pipelines, we help teams: ✅Identify known vulnerabilities (CVEs) in open source components ✅Maintain real-time SBOMs to meet compliance requirements ✅Reduce technical debt and avoid supply chain attacks ✅Automate patching and mitigation in minutes. Whether you're building in Java, .NET, JavaScript, Python, Node.js, PHP, or Go, Meterian supports the languages that power modern applications. Our lightweight, developer-friendly tools ensure DevSecOps and AppSec practices can scale across teams—without slowing down innovation. ✅ Free forever for open source projects ✅ One free private codebase for commercial use ✅ European-based, enterprise-ready, privacy-first Build fast. Fix faster. Stay secure. Visit www.meterian.io to get started.

Website
https://www.meterian.io
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
London, Greater London
Type
Privately Held
Founded
2018
Specialties
java, security, code, .net, javascript, scala, kotlin, ruby, php, python, nodejs, golang, swift, devsecops, Application Security Testing, Open Source, Cyber Security, devops, appsec, Application Security, SAST, DAST, Software Security, Software Engineering, Software Development, Application, and Testing

Locations

Employees at Meterian

Updates

  • View organization page for Meterian

    1,149 followers

    So why audit AI-generated code at the deployment gate? When developers use tools like Cursor or Copilot to commit code in seconds, legacy security checks completely break down. Engineering leads are left with a brutal choice: halt production to fix a package, or ship vulnerable code to hit a deadline. In Part 3 of our series, we break down the fix: Real-Time IDE Scaffolding. Key takeaways: 🔹 IDE-First Security: Moving guardrails directly into VS Code & Cursor so code is vetted the second AI suggests it. 🔹 Automated Remediation: Using MCP servers to give developers clean, safe package alternatives before code is ever committed. 🔹 Zero-Friction DevSecOps: Turning security checks into an invisible formality rather than a deployment blocker. Read the full piece and explore how Meterian HEIDI solves the AI speed problem 👇 https://lnkd.in/ehPb2S9G 💬 How is your team balancing AI developer speed with real-time dependency checks? Let's discuss below! #AISecurity #CyberResilience #AICoding

  • AI coding is so mainstream that OpenAI just launched a physical micro keyboard for Codex users. Developers are moving between GPT-5.6 Sol and Claude Fable 5, handing more of their routine work to coding agents. But what about the security trade-off? You ask an agent to add one feature. It writes the function, recommends a library and gives you the install command. The answer looks polished and the package name looks real. You paste it. This is already a software supply-chain decision. A USENIX Security study analysed 576,000 Python and JavaScript code samples from 16 AI models. At least 5.2% of package references from commercial models and 21.7% from open-source models pointed to packages that did not exist. As these models improve, their output becomes easier to trust. The practical response is simple. Treat every AI-suggested dependency as unverified until its identity, exact version and current security state have been checked. Next week, Meterian will publish an in-depth guide to checking AI-suggested dependencies inside the developer workflow, without slowing development down.

    • No alternative text description for this image
  • A masterclass in treating security as a core engineering feature, not an afterthought. 🔒 #Java ##DevSecOps #Meterian

    View organization page for Open J Proxy

    869 followers

    Open J Proxy 0.5.2-beta is out 🔐 This release includes dependency security fixes for: • CVE-2026-9828 — Logback Core deserialization restriction bypass • CVE-2026-54515 — Jackson Databind deserialization bypass involving @JsonIgnoreProperties Both are moderate-severity issues, but OJP sits between applications and databases, so we treat dependency security as part of the core engineering process — not as an afterthought. Our integrated Meterian scans help us continuously monitor the OJP dependency chain, detect vulnerable versions early, and keep our dependencies free of known vulnerabilities. This release also includes a valuable observability contribution from Youssef Zahi, who implemented CircuitBreakerMetrics for: • current circuit state • state transitions • circuit trips • blocked calls • open duration These metrics give teams better visibility into how OJP protects databases under pressure, especially when circuits open, recover, and prevent overload from cascading. Security, resilience, and observability keep moving forward. Upgrade to Open J Proxy 0.5.2-beta. #OpenJProxy #OJP #Java #OpenSource #CyberSecurity #DevSecOps #Observability #ResilienceEngineering #DatabaseArchitecture

  • One stat from the latest UK Cyber Security Breaches Survey should make business leaders pause. 43% of UK businesses reported a cyber breach or attack in the last 12 months. That is roughly 612,000 businesses. The more worrying detail is what is happening underneath. Among small businesses, cyber risk assessments dropped from 48% to 41%. Cyber continuity plans fell from 53% to 44%. So more businesses are being hit while fewer are checking where they are exposed or how they would recover. A lot of that exposure now sits inside the software stack. Modern applications are built on open-source components, third-party packages and inherited dependencies. They move fast, they save time, and they are everywhere. They can also carry vulnerabilities that teams do not always see until something breaks. Reports suggest 9.8 trillion open-source downloads across major ecosystems in 2025. 87% of audited codebases contained at least one vulnerability. For SMBs, this is where cyber risk becomes a business risk. One vulnerable dependency can disrupt a product, delay operations, affect customers and create costs that were never in the budget. The starting point is simple. Know what is in your software before it becomes the reason your business stops. Check out our blog below. 👇 https://lnkd.in/eZsrxHqB #CyberRisk #Vulnerabilities #OpenSource

  • History shows us what happens when upstream components go unvetted. A single unpatched framework or overlooked library can expose millions of customer records. When AI tools pull from legacy codebases, they risk quietly introducing these exact same systemic liabilities back into your modern stack, putting compliance, operations and customer trust on the line. 👇 Read the full breakdown to discover how to identify and manage these deep-layer risks: https://lnkd.in/eMTQt9KT #SupplyChain #ApplicationSecurity #DevSecOps

  • View organization page for Meterian

    1,149 followers

    A fantastic example of what shifting left looks like in practice. 🚀 We highly value how the Open J Proxy team leverages Meterian to ensure their dependency chain remains secure, resilient, and clear of known vulnerabilities. By treating security as a core engineering process rather than an afterthought, they are continuously protecting the vital space between applications and databases. Congratulations on the 0.5.2-beta release! #vulnerability #opensource #java

    View organization page for Open J Proxy

    869 followers

    Open J Proxy 0.5.2-beta is out 🔐 This release includes dependency security fixes for: • CVE-2026-9828 — Logback Core deserialization restriction bypass • CVE-2026-54515 — Jackson Databind deserialization bypass involving @JsonIgnoreProperties Both are moderate-severity issues, but OJP sits between applications and databases, so we treat dependency security as part of the core engineering process — not as an afterthought. Our integrated Meterian scans help us continuously monitor the OJP dependency chain, detect vulnerable versions early, and keep our dependencies free of known vulnerabilities. This release also includes a valuable observability contribution from Youssef Zahi, who implemented CircuitBreakerMetrics for: • current circuit state • state transitions • circuit trips • blocked calls • open duration These metrics give teams better visibility into how OJP protects databases under pressure, especially when circuits open, recover, and prevent overload from cascading. Security, resilience, and observability keep moving forward. Upgrade to Open J Proxy 0.5.2-beta. #OpenJProxy #OJP #Java #OpenSource #CyberSecurity #DevSecOps #Observability #ResilienceEngineering #DatabaseArchitecture

  • AI was a prominent topic from all the recent technology events in London that Meterian attended, cost reductions in development, time to market, reduction in the time taken on tedious tasks and more. What was not present was conversations around “dependencies”, what is a dependency and why should I be concerned. If your organisation has in-house teams or you are accepting development code from 3rd parties, you need to read this article: https://lnkd.in/emB8dJpF #AI #Dependencies #CISO #AIDevelopment #SoftwareEngineering

    • No alternative text description for this image
  • Threat actors are targeting the insurance sector. Is your open-source supply chain a blind spot? 🛡️ For security leaders in insurance, managing third-party risk is a daily battle. While we secure our perimeters, the growing reliance on Open Source Software (OSS) to process claims and manage data has created new, complex vulnerabilities. Exploits like Log4Shell and the MOVEit transfer breach proved that indirect open-source dependencies are massive targets. With ransomware groups like FIN11 and Cl0p specifically targeting financial and insurance institutions, the stakes have never been higher. To protect sensitive policyholder data, the insurance sector must move beyond reactive patching and adopt proactive DevSecOps strategies: • Adopt SBOMs: Maintain a real-time Software Bill of Materials so you always know exactly what code is running in your environment. • Automate Scanning: Detect zero-days, outdated licenses, and poisoned packages before they hit production. • Tackle Shadow IT: Bring undocumented, unmonitored developer tools under corporate governance. • Plug AI knowledge gaps: Ensure up to date threat intelligence is used as part of AI-assisted coding. OSS security is critical for today’s digital infrastructure. Time to put software composition analysis at the top of the security agenda. Read our blog in comment below. 🔗 👇 #CyberSecurity #CISO #SupplyChainSecurity #InsurTech #DevSecOps #SBOM #RiskManagement

  • Open Source Software is free to use, but it's 𝗡𝗼𝘁 𝗙𝗿𝗲𝗲 𝗳𝗿𝗼𝗺 𝗥𝗶𝘀𝗸 𝗜𝘁’𝘀 𝗮 𝗦𝗼𝘂𝗿𝗰𝗲 𝗼𝗳 𝗘𝘀𝗰𝗮𝗹𝗮𝘁𝗶𝗼𝗻 𝗥𝗲𝗴𝗮𝗿𝗱𝗹𝗲𝘀𝘀 𝗼𝗳 𝘁𝗵𝗲 𝗯𝘂𝘀𝗶𝗻𝗲𝘀𝘀 𝗦𝗶𝘇𝗲 𝗼𝗿 𝗦𝗲𝗰𝘁𝗼𝗿 𝗙𝗿𝗼𝗺 𝗙𝗮𝗰𝘁𝗼𝗿𝘆 𝗙𝗹𝗼𝗼𝗿𝘀 𝘁𝗼 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗦𝘁𝗮𝗰𝗸𝘀: 𝗢𝗦𝗦 𝗥𝗶𝘀𝗸 𝗡𝗼𝘄 𝗠𝗶𝗿𝗿𝗼𝗿𝘀 𝗣𝗵𝘆𝘀𝗶𝗰𝗮𝗹 𝗦𝘂𝗽𝗽𝗹𝘆 𝗖𝗵𝗮𝗶𝗻 𝗧𝗵𝗿𝗲𝗮𝘁𝘀... ☠️ Learn more in our blog linked below. #SoftwareSupplyChain #OSSRisk #SupplyChainSecurity #SBOM #CyberRisk #DevSecOps

  • View organization page for Meterian

    1,149 followers

    𝗧𝗵𝗲 𝗨𝗞 𝗽𝘂𝗯𝗹𝗶𝗰 𝘀𝗲𝗰𝘁𝗼𝗿 𝘀𝘁𝗶𝗹𝗹 𝗿𝘂𝗻𝘀 𝗼𝗻 𝗵𝘂𝗻𝗱𝗿𝗲𝗱𝘀 𝗼𝗳 𝗹𝗲𝗴𝗮𝗰𝘆 𝗜𝗧 𝘀𝘆𝘀𝘁𝗲𝗺𝘀. According to the National Audit Office, government departments identified at least 228 legacy IT systems in March 2024. 28% were red-rated. 53% still had no fully funded remediation plan. That is a serious resilience problem. Legacy systems are hard to patch. They often depend on old software, scarce skills, and architectures that were never built for today’s threat environment. They also rarely sit alone. A legacy application may connect to newer services, internal databases, supplier platforms, or citizen-facing systems. That makes it easier for one weak point to become a wider operational issue. For public services, cyber risk quickly becomes service risk: ❌Housing systems can slow down. ❌Benefits processing can be disrupted. ❌Healthcare operations can be delayed. ❌Sensitive data can be exposed. Modernisation will take time. But visibility can improve much faster. Public sector teams need a clearer view of what is running inside their software, which dependencies are exposed, and where known vulnerabilities still exist. 𝗟𝗲𝗴𝗮𝗰𝘆 𝗜𝗧 𝗰𝗮𝗻𝗻𝗼𝘁 𝗯𝗲 𝘁𝗿𝗲𝗮𝘁𝗲𝗱 𝗮𝘀 𝗮 𝗯𝗮𝗰𝗸𝗴𝗿𝗼𝘂𝗻𝗱 𝗶𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲 𝗽𝗿𝗼𝗯𝗹𝗲𝗺 𝗮𝗻𝘆𝗺𝗼𝗿𝗲. 𝗜𝘁 𝗶𝘀 𝗻𝗼𝘄 𝗽𝗮𝗿𝘁 𝗼𝗳 𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗿𝗲𝘀𝗶𝗹𝗶𝗲𝗻𝗰𝗲. https://lnkd.in/e4AD_-44

    • No alternative text description for this image

Similar pages

Browse jobs