Skip Navigation

Press Releases

The latest scoop on Sonatype.

Sonatype 2017 State of the Software Supply Chain Report Reveals DevOps Practices Reduce Use of Defective Open Source Components by 63 Percent

By actively governing the flow of open source components organizations are improving application quality and developer productivity

Fulton, MD - July 17, 2017 Sonatype, the leader in software supply chain automation, today announced the release of its third annual State of the Software Supply Chain Report. This year’s report highlights risks lurking within open source software components and quantifies the empirical benefits of actively managing software supply chain hygiene.

Sonatype Acquires Vor Security; Introduces Nexus Lifecycle XC

Nexus Open Source Intelligence is extending coverage to include Ruby, PHP, CocoaPods, Swift, Golang, C, and C++ in addition to Java, JavaScript, NuGet, and PyPI

Fulton, MD - June 29, 2017 - Sonatype, a leader in software supply chain automation, today announced that it has acquired Vor Security. Ken Duck, founder and CEO of Vor will join the product and engineering team at Sonatype to continuously expand and refine the open source component intelligence service that underpins the Nexus platform.

Sonatype Integrates Nexus Lifecycle with Microsoft Visual Studio

Delivers automated open source governance to DevOps native teams using Microsoft tools

Fulton, MD - June 20, 2017 - Sonatype, the leader in software supply chain automation, today announced that it has released a new version of Nexus Lifecycle that includes an extension to Microsoft Visual Studio, a popular integrated development environment (IDE). This new Nexus Lifecycle integration empowers millions of Visual Studio developers with direct access to Sonatype's open source intelligence engine so they can easily vet component quality and automatically ensure compliance with defined security, licensing and architectural policies such as component age or popularity.

Sonatype Nexus Repository Recognized as a Certified Red Hat OpenShift Solution

Delivers free third-party Docker private registry for Red Hat OpenShift Container Platform users

BOSTON – RED HAT SUMMIT 2017 – May 1, 2017 – Sonatype, the leader in software supply chain automation, today announced that it has containerized and certified its Nexus Repository to run on Red Hat OpenShift Container Platform. Red Hat OpenShift Container Platform enables developers to quickly build, host, and scale applications in a cloud environment. Red Hat OpenShift Container Platform customers will now be able to deploy Nexus Repository as a solution for managing open source components and containers.

New DevOps Research From Sonatype Reveals Changing Attitudes Toward Application Security in the Financial Services Sector

Top performing software development teams embrace DevSecOps automation.

Fulton, MD – April 25, 2017 – Sonatype, the leader in software supply chain automation, today announced the financial services results of its 2017 DevSecOps Community Survey. 412 financial services IT professionals participated in the online survey conducted in February 2017, out of a total of 2,292 survey respondents.

New DevOps Research From Sonatype Reveals Changing Attitudes Toward Application Security in Government

Top performing software development teams embrace DevSecOps automation

Fulton, MD – April 25, 2017 – Sonatype, the leader in software supply chain automation, today announced the government results of its 2017 DevSecOps Community Survey. 101 public sector IT professionals participated in the online survey conducted in February 2017, out of a total of 2,292 overall survey respondents. The survey revealed that mature development organizations ensure automated security is woven into their DevOps practice early, everywhere, and at scale. Analysis of responses also found that 25% of government organizations continue to struggle with breaches, compared to 20% of all survey respondents.

New DevOps Research From Sonatype Reveals Changing Attitudes Toward Application Security in Telecommunications Sector

Top performing software development teams embrace DevSecOps automation

Fulton, MD – April 25, 2017 – Sonatype, the leader in software supply chain automation, today announced the telecommunications results of its 2017 DevSecOps Community Survey. 160 telecommunications IT professionals participated in the online survey conducted in February 2017, out of a total of 2,292 overall survey respondents. The survey revealed that mature development organizations ensure automated security is woven into their DevOps practice early, everywhere, and at scale. Analysis of responses also found that 20% of telecom organizations continue to struggle with breaches, consistent with overall survey respondents.

Sonatype Announces Free Git LFS Support for Nexus Repository

Fulton, MD – April 20, 2017 – Sonatype, the leader in software supply chain automation, today announced that Nexus Repository is first to market with free support for Git Large File Size (LFS) artifacts. With the addition of Git LFS, Nexus Repository now supports eight of the most popular software component types, including Docker, Java, npm, NuGet, PyPI, Bower, and RubyGems.  

Sonatype Introduces Free Next-Generation Repository Health Check

Fulton, MD – April 19, 2017 - Sonatype, the leader in software supply chain automation, today released the next generation of its free Repository Health Check (RHC) feature within its flagship Nexus Repository product.  As of today, all 120,000 organizations using Nexus will benefit immediately from the ability to automatically analyze the quality and security of open source software components housed within their Nexus Repository as part of their DevOps pipeline.

Sonatype Announces Secure DevOps Solution for Python Developers

Fulton, MD – April 19, 2017  Sonatype, the leader in software supply chain automation, today announced that its Nexus Firewall will offer support for automated governance of PyPI components before the end of the quarter.  Sonatype continues to lead the market in introducing application security technology at the earliest possible phase of the software development lifecycle for DevOps practices.