Fundraising Fox

Mergebase Software Inc.

Acquired

Founded 2018 Β· 1 known investors

MergeBase provides Software Composition Analysis (SCA) tools that detect and manage open-source software vulnerabilities across the software supply chain. The platform helps organizations secure applications, achieve compliance, and reduce their supply chain attack surface through continuous vulnerability management.

Also known as MergeBase

Investors Β· 1

Company profile

researched Aug 2026

MergeBase Software Inc. develops a software supply chain security platform built around Software Composition Analysis (SCA). The platform identifies known vulnerabilities in open-source, third-party and proprietary components, generates Software Bills of Materials (SBOMs), and provides remediation and attack surface reduction capabilities intended to help organizations secure applications and meet compliance requirements.

The product spans the software development lifecycle in three stages: code (direct integrations with GitHub and Bitbucket to flag vulnerable components during in-house development), build (risk assessment with upgrade guidance based on risk, compatibility and component popularity), and runtime (detection of and defence against known vulnerabilities in deployed applications). MergeBase positions its patented Runtime SCA and application hardening as differentiators, using AI to improve accuracy over time and automatically removing access to unused and vulnerable components. The company cites Log4Shell (CVE-2021-44228) as a representative scenario where rapid detection and mitigation of a known vulnerability is required. Alongside the platform, MergeBase publishes a technical blog covering SCA, SBOM generation and compliance, Java and open-source security, container scanning and license compliance, and has extended language coverage to include Rust and Dart.

In June 2024 MergeBase was acquired by Finite State, Inc., a software risk management provider for connected devices and software supply chains, with the stated aim of combining Finite State's binary analysis with MergeBase's source code analysis across the SDLC.

Business model

MergeBase sells its SCA platform to enterprise software and security teams, offering a free entry point ("Start for Free" and free SBOM generation) alongside demo-led enterprise engagement.

Latest developments

In April 2024 MergeBase added Rust and Dart language support and sponsored JDevSummit IL 2024 in Tel Aviv in partnership with Engineering Software Lab. In February 2024 it replaced its CodeGreen product with a new Bitbucket integration aligned to Atlassian's shift to cloud. Bob Lyle joined as Chief Revenue Officer in May 2024 and was scheduled to present at GSMA FASG #29 in Istanbul in June 2024. On 27 June 2024, Finite State, Inc. announced it had acquired MergeBase, combining Finite State's binary analysis with MergeBase's source code analysis, SBOM generation and Runtime SCA.

β–ΈFull profile β€” market position, technology, go-to-market, history

Market position

MergeBase competes in the application security and Software Composition Analysis segment; its acquirer cites third-party projections of a USD 55.0 billion application security market by 2029.

MergeBase describes itself as the only SCA product that detects and defends against known vulnerabilities at runtime, and claims low false-positive rates through prioritization that deemphasizes vulnerabilities in unused code. It states it was the first SCA tool to scan applications built with the Dart language. A referenced customer described MergeBase as detecting more vulnerabilities than other systems tested.

Technology

Software Composition Analysis covering source code and build artifacts, SBOM generation, and a patented Runtime SCA that monitors deployed applications and blocks attacks against vulnerable components. The platform applies AI to continuously improve detection accuracy and to reduce attack surface by automatically eliminating access to unused and vulnerable components; the company states this approach reduces attack surfaces by 60-70% over time. It emphasizes minimizing false positives, deprioritizing vulnerabilities in unused code, and providing upgrade guidance based on risk, compatibility and popularity. Integrations include GitHub, Bitbucket and CI/CD pipelines, and supported ecosystems include Java, .NET/NuGet, containers, Rust and Dart.

Go-to-market

Direct enterprise sales supported by free trials and free SBOM generation, developer-oriented integrations with source-control platforms, content marketing through a technical blog, and industry event participation and sponsorships such as JDevSummit IL 2024 in Tel Aviv and GSMA FASG #29 in Istanbul. In May 2024 the company appointed a Chief Revenue Officer to lead commercial expansion.

Enterprise development, DevSecOps and security teams; published materials reference financial institutions, medical device manufacturers subject to FDA SBOM requirements, energy producers and fintech companies, and Finite State's acquisition rationale extends the offering to embedded systems and connected devices.

History

MergeBase built an SCA platform spanning code, build and runtime stages, expanded language and ecosystem coverage over time (including .NET/NuGet, containers, Rust and Dart), migrated its Bitbucket offering away from the earlier CodeGreen product in early 2024, and was acquired by Finite State, Inc. in June 2024. Oscar van der Meer served as CEO through the acquisition.

Compiled by commissioned research from 4 cited public sources β€” announcements, filings, and press listed under research sources below.

Key figures

latest reported
Stated attack surface reduction over timeJun 202460-70%

Company-reported or press-reported figures, each dated to when it was claimed β€” not independently audited.

Timeline Β· 7

launches, deals, and filings
Jun 2024
Finite State, Inc. acquires MergeBase

Finite State, Inc., a software risk management provider based in Columbus, Ohio, announced the acquisition of MergeBase, combining Finite State's binary analysis with MergeBase's source code analysis, SBOM generation and patented Runtime SCA. Deal terms were not disclosed.

source β†—

Jun 2024
MergeBase to present at GSMA FASG #29 in Istanbul

Bob Lyle and MergeBase announced attendance at GSMA FASG #29 in Istanbul, June 25-27, 2024.

source β†—

May 2024
Bob Lyle appointed Chief Revenue Officer

MergeBase announced the appointment of Bob Lyle as Chief Revenue Officer.

source β†—

Apr 2024
Rust language support added to MergeBase SCA

MergeBase added support for scanning and securing applications built with the Rust programming language.

source β†—

Apr 2024
Dart language support added to MergeBase SCA

MergeBase added Dart language support, described by the company as the first SCA tool to scan applications built using Dart.

source β†—

Apr 2024
Sponsorship of JDevSummit IL 2024 and partnership with Engineering Software Lab

MergeBase announced sponsorship of JDevSummit IL 2024 in Tel Aviv and a partnership with Engineering Software Lab.

source β†—

Feb 2024
New MergeBase-Bitbucket integration replaces CodeGreen

MergeBase replaced its CodeGreen product with a new Bitbucket integration to support Atlassian's shift to Cloud.

source β†—

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

β–ΈResearch sources Β· 4

primary sources listed

4 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Mergebase Software Inc. do?
MergeBase is a software supply chain security vendor offering Software Composition Analysis, SBOMs and runtime protection.
Who are Mergebase Software Inc.'s investors?
Mergebase Software Inc.'s investors include WUTIF Capital.