About Sonatype

Sonatype in the News

Help Net Security

The insecurity of the component lifecycle

Published May 02, 2013 08:00

Open source component use continues to skyrocket with applications now more than 80 percent component-based, while at the same time organizations continue to struggle with establishing policy to secure and govern component use. According to the Sonatype survey, 76 percent of organizations have no component management policies in-place.

more
Infosecurity Magazine

Three-fourths of organizations lack app component policy

Published May 01, 2013 08:00

When it comes to developing applications, open-source component use continues to skyrocket. And like operating systems or databases, open-source components represent a rich attack vector for hackers to exploit given their commonality across organizations and applications.

more
SD Times

Sonatype ushers in new era of application security aimed at eliminating risk in the modern software supply chain

Published April 30, 2013 08:00

Sonatype, the leader in Component Lifecycle Management (CLM), today introduced a revolutionary new approach to application security which significantly reduces the risk in using freely available, open source software (OSS) components. Sonatype CLM is the first and only solution to secure the entire component lifecycle – from design, development and deployment through production operations.

more
SD Times

Keeping Tabs on Open-Source Components

Published April 19, 2013 08:00

It’s not uncommon for a software application today to consist of 80% or more open-source components, which explains enterprises’ growing use of repository managers, solutions that help them govern what open-source components are being used by their developers.

more
Open Source and the Software Supply Chain: A Look at Risks vs. Rewards

Open Source and the Software Supply Chain: A Look at Risks vs. Rewards

Published March 01, 2013 04:52

There is a dynamic shift occurring in the software development landscape. No longer are applications written, today most are assembled using open source components. The growing reliance on externally sourced, open-source components as core building blocks for modern application development, coupled with the complexity of the ecosystem, has ushered in new risks for the software supply chain. This article will explore the licensing, security, and quality risks associated with component-based development and its direct impact on the integrity of the software supply chain.

more
News Source The H

The Ghost of a Spring Framework Bug Haunts Old Code

Published January 18, 2013 09:29

There are reports of the discovery of a remote code execution flaw in the Spring Framework, but many are not mentioning that the flaw in question was fixed over a year ago and that what has been found is actually a new way to exploit that old flaw. In 2011, a "variable" severity flaw, identified as CVE-2011-2730, was discovered by two researchers in versions 3.0.0 to 3.0.5, 2.5.0 to 2.5.6SEC02 and 2.5.0 to 2.5.7SR01. more
News Source Infosecurity

Remote Code Vulnerability in Spring Framework for Java

Published January 17, 2013 09:20

Spring Framework, an open-source Java development framework developed by SpringSource and used by software developers to produce business-critical applications, includes a vulnerability that could lead to remote code execution. more
News Source Security Week

Remote Execution Flaws a Risk to Spring Framework Applications

Published January 16, 2013 09:24

Another Web framework, another flaw. Just days after Ruby on Rails maintainers closed bugs in the popular Web framework, researchers highlighted a remote injection vulnerability in the Spring Framework and associated problems that went along with it. more

Awards

  • Gartner
  • NVTC
  • Red Herring
  • RSA
  • INC 500
  • SD Times
  • Codie