Gartner logo

Gartner Security & Risk Management Summit

Date: June 8-11, 2015
Location: National Harbor, MD

This year’s Gartner Security & Risk Management Summit shows you how to find the balance between enabling your organization to move forward against its objectives while also protecting it, your customers and employees, so you can have faster business process and improved ROI. You’ll gain a comprehensive outlook into the full spectrum of security and risk management emerging trends and market scopes within five role-based programs and a dedicated Technical Insights track.

more
InfoSec logo

InfoSecurity EU

Date: June 2-4, 2015
Location: London, UK

Infosecurity Europe is Europe's number one information security event. Featuring over 345 exhibiting vendors and services suppliers with the most diverse range of new products and services, an unrivalled education program and over 15,000 industry professionals travelling from over 70 countries, it is the most important date in the calendar for Information Security professionals across Europe. Visit Sonatype at booth G172.

more
OWASP logo

OWASP AppSecEU 2015

Date: May 19-22, 2015
Location: Amsterdam, NL

OWASP AppSecEU is the premier gathering place for executives from Fortune 500 companies and technology thought leaders. It offers cutting-edge research presented by security professionals across Europe, trainings and speeches on a variety of security topics including: cloud security, mobile security, vulnerability analysis, and much more. There will be small group sessions, workshops, and learning opportunities for developers, business owners, and security experts. Learn and network for four days, while discovering Amsterdam!

more
RSA Conference

RSA Conference

Date: April 20-24, 2015
Location: San Francisco, CA

RSA Conference is helping drive the information security agenda worldwide with annual industry events in the U.S., Europe and Asia. Throughout its history, RSA Conference has consistently attracted the world's best and brightest in the field, creating opportunities for conference attendees to learn about IT security's most important issues through first-hand interactions with peers, luminaries and emerging and established companies. As the IT security field continues to grow in importance and influence, RSA Conference plays an integral role in keeping security professionals across the globe connected and educated.

more
Gartner logo

DevNexus

Date: March 10-12, 2015
Location: Atlanta, GA

DevNexus is the premier conference for professional software developers who want to hear from and interact directly with internationally acclaimed presenters and technologists. While you’re here, you’ll also connect with like-minded developers who are mastering their craft in a wide range of today’s most relevant technologies and have the chance to hear Sonatype's Mark Miller present his talk entitled "Wait Wait, Don't Pwn Me!"

more
Sonatype Webinar

Cyber Startup Summit

Date: January 28-30, 2015
Location: IDEALondon | Google Campus

The Cyber Startup Summit has the primary focus to promote innovation across cyber security. It is to enable collaboration between enterprise security leaders, security startups, creative entrepreneurs, students and academics to discuss, connect and hack the hot topics within the world of cyber security.

more

Nexus Live: October 9, 2014 1:00pm EDT, TheNEXUS Community Sneak Peak

On-Demand Recording: Streamed October 9, 2014

During the October 2014 broadcast of Nexus Live we were able to catch up with Gene Kim and Josh Corman to find out what’s in store for the DevOps Enterprise Summit in the Bay Area at the end of the month. We also took a quick look at TheNEXUS, the new community site for Nexus, Nexus Pro and CLM. Take a look.

more
Sonatype Webinar

Webinar: See the Sonatype Product Roadmap Revealed

Original Broadcast Date: September 25, 2014

For years, development teams and now security professionals have looked to Sonatype for better management of open source and third party components across the software supply chain. Watch our live product roadmap discussion to learn more about our commitment to helping you achieve real business value from your enterprise applications more quickly - with efficiency, quality and security addressed across the software lifecycle. See how with new product advancements for more component languages, a consolidated risk management dashboard and expanded integration points across the SDLC can bring your organization enterprise-class component management to your development operations.

more
Sonatype Webinar

ISSA Webinar: What's in your Software? Identifying Open Source Vulnerabilities

Date: September 23, 2014
Time: 12:00pm EDT

New software enters our security ecosystems daily. When we evaluate the software we look for vulnerabilities in the product. Of course we run functional tests, or break out our favorite scanner, to see if there is embedded malware or dangerous deployment requirements, or even bugs in the program. When done, it gets deployed. What happens after deployment is important, but also gets missed. Of course we will catch new vulnerabilities that are directly related to the product, but what about vulnerabilities in the third party components included in the product? Recently this point was driven home by the numerous vulnerabilities in OpenSSL. Most people usually hear about it when it comes as an update from the vendor. What can you do about it? This panel will leverage the insight from seasoned industry leaders as we hear their thoughts.

more
Sonatype Webinar

Webinar: Open Source Development and Application Security Survey: The Results are In!

Over 3,300 participated! The final results of our 4th Annual Open Source and Application Security Survey are in. Adrian Lane from Securosis and Brian Fox from Sonatype provide a detailed breakdown of the findings from a developer and an application security perspective. They discuss policies, practices, and breaches as well as how organizations can use these results to create constructive conversations to feed their open source security management practices.

more

RSA Webinar: Software Liability?: The Worst Possible Idea (Except for all Others)

On-Demand Recording: Streamed Thursday, May 29, 2014

While many had hoped that market competition would influence security improvements, customers are forced to accept software as is with no alternatives. Software is responsible for our critical infrastructure, cars, medical devices and is a part of our daily lives including our well-being. Will we be able to achieve better software security without vendors facing financial consequences?

more
Sonatype Webinar

Webinar: Lessons Learned from Heartbleed, Struts and the Neglected 90%

On-Demand Recording: Streamed May 1st, 2014

Watch this insightful and witty discussion between two old pals, Wendy Nather, Security Research Director at 451 Research and Josh Corman, CTO at Sonatype on the state of application security today. They share their perspectives on the changing landscape of application development and how this is impacting common application security approaches. They agree the dramatic shift from source code to component based development has created an open source security gap. With component vulnerabilities becoming national news, Heartbleed, Struts and the promise of more to come, now is the time to address this growing security gap.

more
Sonatype Press Release

Webinar: FS-ISAC Best Practices for Managing Risk from Open Source Libraries & Components

On-Demand Recording

In December of 2013, the FS-ISAC Third Party Software Security Working Group released new controls to manage risk associated with open source libraries and components. These controls recommend financial institutions apply policy management and enforcement as well as inventory management for open source libraries and components used in their application portfolio. Webinar features Jim Routh, Aetna's Chief Security Officer and Joshua Corman, Sonatype's Chief Technology Officer.

more

Nexus Live: December 2013 with Tyler Jewell, CEO of Codenvy

On-Demand Recording: Streamed December 19, 2013

Watch our December Nexus Live event featuring Tyler Jewell, CEO of Codenvy. Codenvy runs a cloud based development and deployment environment in a true devops fashion. Tyler shares how Codenvy uses Nexus as part of their build pipeline.

more

Nexus Live: November 2013 with Kyle Allan from Riot

On-Demand Recording: Streamed November 21, 2013

We continued our DevOps focus for the month of November and were joined by Kyle Allan from Riot Games. Kyle shared how Riot Games uses Chef to install Nexus. He also shared how they are using the Nexus REST API in the command line interface and a Nexus cookbook he has open sourced. Watch the recording to learn how to extend the value of Nexus into your deployment environment.

more

Nexus Live: October 2013 featuring Puppet

On-Demand Recording: Streamed October 23, 2013

Learn how Hubspot.com developed a system using Puppet that provisions Nexus instances into a deployment platform in a DevOps manner.

more

Nexus Live: September 2013 featuring the Nexus user survey

On-Demand Recording: Streamed September 11, 2013

Watch our live panel discussions with Nexus experts where they highlight survey results from our most advanced Nexus users. Learn what development tools work with Nexus, what features users value most and see how over half of users survey are interested in extending component management beyond their repository manager.

more

Nexus Live: July 2013 profiling Nexus with JMX

On-Demand Recording: Streamed on July 17, 2013

Watch our July session to learn how to profile your Nexus installation with JMX and hear from the Maven creator, Jason van Zyl on the highlights of the newest Maven 3.1.0 release.

more

Nexus Live: June 2013 improving security, build promotion & staging

On-Demand Recording: Streamed June 19, 2013

Learn how you can extend your repository manager strategy to improve the security and quality of your applications. Find out how you can simplify your build promotion and staging with recent Nexus Pro enhancements. Also, learn how you can use Gradle to deploy components to Nexus.

more

Nexus Live: May 2013 focus on Repository Healthcheck

On-Demand Recording: Streamed May 31, 2013

See the most popular feature of Nexus in action, get a complete overview of the Repository Health Check to assess the health of the components in your repository. Avoid risks by reviewing popularity, license type and security vulnerabilities for every component in the repository. Also see an early preview of Nexus 2.6.

more

Awards

Codie INC 500 Red Herring SD Times NVTC RSA Gartner