I'm writing several posts using my favorite quotes from the recent Security at the Speed of Development webinar with Wendy Nather, Research Director, Security for 451 Research and Ryan Berg, Sonatype CSO.
In this first post, Wendy was talking about the need to integrate security in from the beginning...
The interesting thing about Wendy's recommendation is that it represents a key design principle of the Sonatype CLM. Integrating security throughout the entire lifecycle - from design, development, on through production deployment.
With the CLM, it starts by providing security, licensing and quality information in the IDE so the developer can make informed decisions about the best components to use. This prevents problems from occurring downstream, problems that become more expensive to fix.
To learn more about Sonatype CLM, check out the product tour.
Make sure you read Wendy's research Mission Impossible: securing the open source software supply chain with Sonatype.