Skip Navigation

Press Releases

The latest scoop on Sonatype.

Sonatype and Partners Host 30,000 Professionals at All Day DevOps 2017

100 presentations delivered by DevOps experts and IT thought leaders

Fulton, MD – October 24, 2017 Sonatype, the leading provider of software supply chain automation announced today that it is hosting more than 30,000 global attendees at All Day DevOps 2017, the largest virtual conference in the world dedicated to sharing DevOps best practices.  The second annual event started live streaming at 8:00am GMT today (3:00am New York, 7:00pm Sydney), and continues for 24 hours straight.

Sonatype Reports 78% Year-Over-Year Growth

Equifax and GDPR accelerate global demand for managed software supply chains in Q3.

Fulton, MD – October 18, 2017 — Sonatype, the leader in software supply chain automation, today announced continued growth across every aspect of its Nexus software business. Comparing Q3 year-over-year results, Sonatype reported:

  • 78% growth in total annual contract value (ACV) sold
  • 200% increase in Nexus Lifecycle utilization to 720,000 applications per month
  • 60% increase in active users of Nexus Repository Manager to 1.8 million developers

Sonatype Bolsters Executive Team, Adds Former IBM Cloud General Manager

Enterprise DevOps Veteran, Bill Karpovich, Joins Sonatype to Drive Continued Growth & Global Expansion

Fulton, MD – October 12, 2017 Sonatype, the leader in software supply chain automation, today announced that Bill Karpovich has been named SVP of strategy and corporate development. Reporting to Sonatype CEO Wayne Jackson, Bill will lead portfolio evolution, strategic partnering, acquisitions, and new growth initiatives worldwide.

Sonatype Warns Additional Breaches Loom Post-Equifax

In the past year, 3,054 organizations downloaded the same Struts2 component exploited in Equifax hack

Fulton, MD – September 18, 2017 - Sonatype, the leader in software supply chain automation, today released new data on the number of organizations that have downloaded vulnerable versions of the Struts2 component (CVE-2017-5638) exploited in the massive breach at Equifax.

Letitia Long and Steve Hills Join Sonatype Board of Directors

Award-winning company adds distinguished leaders to help shepherd continued growth

Fulton, MD – August 15, 2017 - Sonatype, a leader in software supply chain automation and a Deloitte Fast 500 company, today announced that Letitia Long, the former director of the U.S. National Geospatial-Intelligence Agency (NGA) and Steve Hills, the former president and general manager of The Washington Post, have joined its board as independent directors.  Long and Hills will serve alongside board representatives from Sonatype’s lead investors Goldman Sachs, Accel Partners, New Enterprise Associates, and Hummer Winblad Venture Partners.

Sonatype’s Nexus Lifecycle Measures the Performance of Better, Faster DevOps

Software development teams automating open source component governance improve application quality by 63%

Fulton, MD – August 10, 2017 – Sonatype, the leader in software supply chain automation, today announced support of new application quality and ROI metrics within its Nexus Lifecycle solution. The new feature, known as Success Metrics, enables DevOps teams to quickly assess and measure the efficacy of their automated open source governance programs.

Sonatype Adds Native Container Scanning to Nexus Lifecycle

DevOps teams can now automatically and continuously examine the quality of open source components used in containerized applications

Fulton, MD  August 10, 2017 - Sonatype, the leader in software supply chain automation, today released a new version of its popular Nexus Lifecycle product which now includes a built-in service that enables software development teams to automatically and continuously examine the security and quality of open source components used within container images.

Sonatype 2017 State of the Software Supply Chain Report Reveals DevOps Practices Reduce Use of Defective Open Source Components by 63 Percent

By actively governing the flow of open source components organizations are improving application quality and developer productivity

Fulton, MD - July 17, 2017 Sonatype, the leader in software supply chain automation, today announced the release of its third annual State of the Software Supply Chain Report. This year’s report highlights risks lurking within open source software components and quantifies the empirical benefits of actively managing software supply chain hygiene.

Sonatype Acquires Vor Security; Introduces Nexus Lifecycle XC

Nexus Open Source Intelligence is extending coverage to include Ruby, PHP, CocoaPods, Swift, Golang, C, and C++ in addition to Java, JavaScript, NuGet, and PyPI

Fulton, MD - June 29, 2017 - Sonatype, a leader in software supply chain automation, today announced that it has acquired Vor Security. Ken Duck, founder and CEO of Vor will join the product and engineering team at Sonatype to continuously expand and refine the open source component intelligence service that underpins the Nexus platform.

Sonatype Integrates Nexus Lifecycle with Microsoft Visual Studio

Delivers automated open source governance to DevOps native teams using Microsoft tools

Fulton, MD - June 20, 2017 - Sonatype, the leader in software supply chain automation, today announced that it has released a new version of Nexus Lifecycle that includes an extension to Microsoft Visual Studio, a popular integrated development environment (IDE). This new Nexus Lifecycle integration empowers millions of Visual Studio developers with direct access to Sonatype's open source intelligence engine so they can easily vet component quality and automatically ensure compliance with defined security, licensing and architectural policies such as component age or popularity.