What I Learned Talking to 45 CISOs About DevSecOps

Recently, I moderated round table discussions between dozens of CISOs at Evanta CISO Summits in Chicago and Atlanta, and my colleague, Michelle Dufty, moderated a similar event in San Francisco.
The post What I Learned Talking to 45 CISOs About De… Continue reading What I Learned Talking to 45 CISOs About DevSecOps

Shifting Security Left: The Innovation of DevSecOps

What is DevSecOps? It involves taking all the practices of DevOps and pulling in security practices to improve security. Tom Stiehm (@thomasstiehm) explains the process.
The post Shifting Security Left: The Innovation of DevSecOps appeared first o… Continue reading Shifting Security Left: The Innovation of DevSecOps

Continuous Delivery For All

Jez Humble’s (@jezhumble) career has spanned roles through coding, infrastructure, and product development across three continents and organizations of varying sizes. To say he knows a lot about continuous delivery is a total understatement…. Continue reading Continuous Delivery For All

Sonatype Nexus is Rising Above the Swamp

In case you missed it — our rival JFrog published this blog post on Thursday.  Amidst the hyperbole, JFrog made a few statements that are true, and numerous that are rooted in fear mongering, falsehoods and gimmicky marketing tactics.  … Continue reading Sonatype Nexus is Rising Above the Swamp

Gartner: Mitigate Risk By Hardening the Software Supply Chain

When molten steel is immersed in water it transforms into one of the world’s strongest materials. A resilient software supply chain is no different. Hardened steel requires combining alloys; a hardened software supply chain requires combinin… Continue reading Gartner: Mitigate Risk By Hardening the Software Supply Chain

Take Our Survey: Microservices, Containers, and Serverless Development

Sonatype is working on improving the overall experience when dealing with microservices, containers, and serverless development such as AWS Lambdas or Azure Functions. We would love to understand your needs. If you are excited about microservices,… Continue reading Take Our Survey: Microservices, Containers, and Serverless Development

Vista Acquires a Majority Interest in Sonatype: A Great Day for our Customers, Partners and Community

The Sonatype journey started more than a decade ago, just as the concept of “open source” and componentized software development was gaining steam. From our humble beginning as core contributors to Apache Maven, to supporting Maven Cen… Continue reading Vista Acquires a Majority Interest in Sonatype: A Great Day for our Customers, Partners and Community

Sonatype Partners with All Day DevOps to Deliver the Largest DevOps Conference for 36,000

Four years ago, my colleague Mark Miller and I founded the All Day DevOps conference with seven friends from around the community.  We planned the conference in 90 days and expected 1,000 folks to show up to listen to the 57 speakers we had v… Continue reading Sonatype Partners with All Day DevOps to Deliver the Largest DevOps Conference for 36,000

How The Unicorn Project Aligns with The Phoenix Project

Editor’s Note: You can meet Gene at the 2020 DevOps Enterprise Summit (DOES) October 28-30 in Las Vegas. Visit the Sonatype booth to receive a free copy of The Unicorn Project. DOES explores everything related to open source security, at scale. So… Continue reading How The Unicorn Project Aligns with The Phoenix Project