Fulton, MD – April 7, 2020 -- Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today published findings from its seventh annual DevSecOps Community Survey, based on responses from 5,045 software engineering professionals. The survey, developed and conducted in partnership with Carnegie Mellon’s Software Engineering Institute, CloudBees, DevOps Institute, DevOps.com, DevSecOps Days, NowSecure, Security Boulevard, Verica, and All Day DevOps, pulls back the curtain on successful DevSecOps practices, significant influences on developer satisfaction, trends in secure coding, and application breaches.
Nexus Lifecycle now allows users to scan applications for open source software vulnerabilities, automatically enforce open source governance policies, and easily remediate open source risk for 27 different languages and package formats.
Fulton, MD – March 12, 2020 -- Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today announced it’s further expanded its language coverage within Nexus Lifecycle to include Conan (C/C++), Composer (PHP), and RubyGems (Ruby), including the ability to create and contextually enforce policies. By continuing to increase support for the most popular component formats, Nexus Lifecycle is helping millions of developers and security professionals to automatically govern open source hygiene across every phase of the software development lifecycle (SDLC).
Key Partners from Europe, Middle East, Africa and Russia Honored at 4th Annual Sonatype Partner Awards on March 5th, 2020.
AMSTERDAM – March 5, 2020 -- Sonatype, the company that scales DevOps through open source governance and software supply chain automation, announced its EMEA and International channel partner program grew more than 100% in revenue over the last three years. The company’s rapidly growing channel partner ecosystem, which has helped exponentially expand the reach of its automated DevSecOps platform, will be honored at Sonatype’s Fourth Annual EMEA Partner Summit in Amsterdam.
Enhanced solutions take advantage of new algorithms to better identify security vulnerabilities in open source npm packages
Fulton, MD – March 3, 2020 -- Sonatype, the company that scales DevOps through open source governance and software supply chain automation, announced an enhanced suite of JavaScript intelligence capabilities that provides developers with improved accuracy, increased policy control, and faster remediation of open source vulnerabilities across the entire software development lifecycle (SDLC).
Fulton, MD – February 24, 2020 -- Sonatype, the company that scales DevOps through open source governance and software supply chain automation, now includes native support for Helm in Nexus Repository (NXRM). Additional support for developers using Helm Chart Repositories, and by extension Kubernetes, is part of the company’s commitment to strengthening container-based development and ensuring NXRM always enables users to universally manage software libraries and build artifacts.
With the Sonatype Nexus Platform, Eficode helps customers understand the importance of shifting left and automating open source security across the DevOps pipeline
Helsinki, Finland, Nov. 27, 2019 -- Today, Eficode, the European leader in DevOps that is designing, optimising, and managing today’s evolving software development lifecycle processes with its DevOps Platform Eficode ROOT, announced a partnership with Sonatype, the inventors of software supply chain automation, to bring open source governance to its rapidly-growing customer base.
Nexus Lifecycle delivers open API for best-in-class policy control for all container layers
Fulton, MD – Monday, Nov. 25 2019 - Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today announced an open API that makes it easy for third-party container scanners to integrate with Nexus Lifecycle and equip engineering teams with a holistic solution to automatically and accurately control risk related to containers traversing the modern software development lifecycle (SDLC).
Partnership to Accelerate Global Growth and Innovation for Automating Open Source Governance and Software Supply Chain Hygiene
FULTON, MD - November 18, 2019 - Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today announced it has signed a definitive agreement to receive a majority investment from Vista Equity Partners (“Vista”), a leading investment firm focused on empowering and growing enterprise software, data and technology-enabled companies that are reinventing industries and catalyzing change. The partnership with Vista will allow Sonatype to further fast-track growth and enhance its Nexus product portfolio. Several of Sonatype’s existing investors will retain a stake in the company.
New Integrations Deliver Enterprise-Grade Open Source Governance and Dependency Management to Millions of GitHub Developers
San Francisco - GitHub Universe – Tuesday, Nov. 12, 2019 –Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today announced new integrations that strengthen GitHub with premium open source governance and dependency management controls.
The 2019 event has garnered the largest audience yet to participate in 24 hour conference starting at 3 am ET on November 6
McLean, Va -- Nov. 5, 2019 - Sonatype, the company that scales DevOps through open source governance and software supply chain automation, has partnered with All Day DevOps, the largest conference in the world dedicated to sharing DevOps best practices, on its fourth annual event, streams live for 24 hours starting at 8:00 am GMT on Nov 6, 2019 (3:00 am ET).