Ask any software developer, and they will tell you the truth about two things:
Rather than slowing developers down with process-heavy security gates or circuitous code quality alerts, we believe developers are better served by providing them with gentle, timely, and effective nudges that actually help them improve the quality and security of the applications they are building.
This is why, today, we're announcing the acquisition of MuseDev.
MuseDev is a startup that was incubated by Galois, Inc. and spun out in fall of 2019 by founders Dr. Stephen Magill, Andrew Yorra, and Tom DuBuisson. The Muse product is a cloud-native and innovative source code analysis platform that is uniquely friendly to developers. With a few simple clicks, Muse installs into any source control repo, and automatically begins to analyze pull requests, and provides developers with accurate and actionable feedback so they can easily fix more bugs during peer code review.
Any developer can get started with Muse in seconds. Muse aggregates and orchestrates 24 pre-configured code analyzers that range from "light weight linters" to "deep static analysis tools." It also covers a wide variety of coding languages and bug types, including security, reliability, performance, and style. Today, Muse integrates with GitHub, GitLab, and Bitbucket, and supports Java, JavaScript, Python, .NET, Go, and Ruby code.
Integrating with the pull request workflow is critical when it comes to developer adoption. Through its experience in working with large scale enterprise development teams, MuseDev found that when bugs are accurately identified and surfaced inside the pull request workflow, developers are 70 times more likely to fix them. But Muse does not stop there. Muse is constantly getting smarter -- providing developers feedback expressly on bugs that they are most likely to fix.
Adding Muse to our portfolio will offer tremendous value to our customers who are looking to improve the quality of code they write. I'm also very pleased to announce that all MuseDev employees will join Sonatype to help us continue to build and deliver upon its robust roadmap. You can expect the first Muse technology integrations being released from Sonatype in the Spring of 2021.
But wait, I’ve got even more developer-friendly goodness to share.
At the same time we're expanding our portfolio with the acquisition of MuseDev, I've also been spending a lot of time with our customers to better understand their evolving needs and challenges around software supply chain management. As security concerns around supply chains were ushered to center stage, our customers turned to us as trusted advisors asking for broader, deeper, and more intelligent solutions. We're answering that call, louder and more convincing than ever.
Today, we're excited to unveil the next-generation Sonatype Platform offering customers full-spectrum control of the cloud-native software development lifecycle including: third-party open source code, first-party source code, infrastructure as code (IaC), and containerized code.
Building upon the foundation of our ever-popular artifact repository — Sonatype Nexus Repository — and its best-in-class software composition analysis duo — Sonatype Lifecycle and Sonatype Repository Firewall, Sonatype has bolstered its portfolio to include:
Furthermore, in keeping with our long standing commitment to the open source developer community, we've created advanced migration support for open source projects scrambling to find homes on the heels of Bintray and JCenter sunsetting. Open source projects can easily migrate their packages to a free Sonatype Nexus Repository instance and/or Maven Central host.
As an added bonus to community members, we recently upgraded our free security analysis report — making it available to any open source project hosting code on Maven Central as part of its OSSRH service. This migration support aims to ensure developers experience no downtime or build delays for their software supply chains that rely on public code repositories.
Beginning today, Sonatype customers can expand beyond our best in class open source governance and repository solutions, and will be able to leverage the unique benefits of Muse to help their developers easily find and fix more bugs during peer code review.
The acquisition of Muse and the delivery of our full-spectrum software supply chain management portfolio comes amid continued record growth for Sonatype. We now count 70% of the Fortune 100 as customers and support more than 2,000 commercial engineering teams. Today, the combination of Sonatype's commercial and open source tools are trusted by nearly 15 million developers around the world.
Welcome Muse, to Sonatype! We're excited to have you!