Smart Teams Use Atlassian and Sontaype to Plan Development Work

Jira software from Atlassian is one of the most widely used software in the world, helping agile development teams plan projects and manage stories, epics, tasks, tickets, workflows and backlogs.
Smart developers use Sonatype’s Nexus Platform to a… Continue reading Smart Teams Use Atlassian and Sontaype to Plan Development Work

43% of Data Breaches Connected to Application Vulnerabilities: Assessing the AppSec Implications

Web applications are a growing focus point for cyber criminals. Motivated by financial outcomes, they understand the value of the information exchanged and stored in web applications. The 2020 Verizon Data Breach Investigations Report (DBIR) confirms t… Continue reading 43% of Data Breaches Connected to Application Vulnerabilities: Assessing the AppSec Implications

New in Nexus Repository 3.23: Nexus Intelligence via npm audit

We are excited to announce the official release of Nexus Repository 3.23. In this release, we continue the story of our enhanced JavaScript support with the new Nexus Intelligence via npm audit feature** available to both Nexus Repository OSS and … Continue reading New in Nexus Repository 3.23: Nexus Intelligence via npm audit

New Language? No Problem. New Ecosystems in Nexus Lifecycle and Nexus Firewall

A few months ago we announced some exciting ecosystem updates to Nexus Lifecycle. Today, I’m happy to expand upon that with the news of even more ecosystem coverage added to Nexus Lifecycle, as well as some new additions to Nexus Firewall.
T… Continue reading New Language? No Problem. New Ecosystems in Nexus Lifecycle and Nexus Firewall

Real Talk: What Users Really Look For in a Software Composition Analysis (SCA) Solution

A few weeks ago, we wrote about the differences in SCA and SAST tools. While you can’t really compare the two, for most organizations, software composition analysis (SCA) is likely the best place to start. We also mentioned if you do choose … Continue reading Real Talk: What Users Really Look For in a Software Composition Analysis (SCA) Solution

Nexus Repository: A Strategic Guide from Git to Governance

As leaders of organizations, innovators of technology, and practitioners of continuous development, we must understand the constant changes in the industry to better suit the needs of the business and of our customers. 
The role of modern sof… Continue reading Nexus Repository: A Strategic Guide from Git to Governance

Keep Applications Secure in Atlassian Bitbucket with Automated Pull Requests

As development organizations seek to innovate faster and build more secure applications at scale, one of the trends we’re seeing is the desire to automate dependency management and bring security into the places where developers spend most o… Continue reading Keep Applications Secure in Atlassian Bitbucket with Automated Pull Requests

SAML/SSO Authentication and Conan in Nexus Repository 3.22

Introducing the release of Nexus Repository 3.22. Our product teams are excited to announce SAML/SSO authentication for Nexus Repository Pro. In addition to SAML/SSO, this release includes proxy support for Conan native format in both Nexus Reposi… Continue reading SAML/SSO Authentication and Conan in Nexus Repository 3.22

Developers Gain Contextual Feedback with Automated Pull Request Commenting

At Sonatype, we work continuously to increase awareness of open source risk, and decrease the time it takes you to make your applications safe. It is our never ending quest to shift security left. We’ve rolled out even more granular and auto… Continue reading Developers Gain Contextual Feedback with Automated Pull Request Commenting