Forrester Recognizes Sonatype as a Leader in Software Composition Analysis (SCA)
By Brent Kostak
3 minute read time
This week, independent analyst firm Forrester released it's The Forrester Wave™: Software Composition Analysis (SCA), Q3 2021, following an in-depth evaluation of 10 SCA solutions.
We're thrilled to announce that the Sonatype Platform was recognized as a leader with the highest score in the market presence category among all companies evaluated.
This is an achievement we're proud of. We believe it highlights the incredible work our team has done in building a solution that automates all parts of software supply chain security with an emphasis on open source security. More importantly, it shows how vital it is for organizations to have total control of their cloud-native development life cycles, including third-party open source code, first-party source code, infrastructure as code (IaC), and containerized code.
You can get the full report or continue reading for some of our key takeaways and what we've been working on at Sonatype.
Stellar Policy Management, Underpinned by Precision Data
The Forrester report notes:
"Policy is an area of strength for Sonatype, with out-of-the-box policies that align to a range of standards (particularly in the IaC pack) and a policy engine that allows users to create and assign policies to certain types of applications."
Core to who we are is giving organizations control of their code and the code that makes it into production applications. Across the Sonatype Platform, customers can create custom security, license, and architectural policies based on application type or organization and contextually enforce those policies across every stage of the software development life cycle (SDLC).
But, our policy management is only as good as our data. Precision matters. We pride ourselves on having the most expansive, most in-depth and most actionable database of open source components and vulnerabilities. We examine fingerprints – not just file names and package manifests – to precisely identify risk with Advanced Binary Fingerprints (ABF). It's this precision that lets us promise low false positives and negatives. So when our customers set a policy, they know they can trust it.
Helping Our Customers Is in our DNA
Also noted in the Forrester report:
"Sonatype's customer success team is a major part of its strategy, and customer references appreciate the "very attentive" customer service, with one calling it out as "something that deserves recognition."
If we have a secret weapon to our success, it is our incredible customer success team. Over the years, we've made a conscious effort to build up this program - and have created a support model that provides resources for all sizes of customers, and meets them where they are.
Our customers rely on us for both product-led information, as well as formal training and guidance, to help educate on the development process. Furthermore, we've created a customer portal that acts as a central hub for learners. In addition to documentation, best practice guides, and user community, it provides access to e-learning and training resources, including videos. It's available for anyone interested in learning Sonatype products, as well as those focused on eliminating vulnerable components from their applications and reducing license risk.
If you haven't already, head over to my.sonatype.com and look around at all the valuable resources. We think you'll like what you see.
Expanded Portfolio and Full-Spectrum Software Supply Chain Automation
Last, but certainly not least, in March, we announced our "new" Sonatype Platform that helps make the lives of developers and security teams easier. The Forrester report touches on these expansions as an area that makes Sonatype strong.
As security concerns around supply chains were ushered to center stage this year, our customers turned to us as trusted advisors, asking for broader, deeper, and more intelligent solutions. We answered the call swiftly, and rolled out solutions offering customers full-spectrum control of the cloud-native software development life cycle, including:
-
Third-party open source code
-
First-party source code
-
IaC
-
Containerized code
-
InnerSource
We believe Forrester recognizes that while a big part of SCA remains open source security, it's become so much more than that, just as we do.
What's Next for Sonatype?
The industry continues to evolve, and so is Sonatype. We'll continue to drive key automation and precise data, as well as help customers handle their development cycles. All while focusing on our core of helping organizations build better software faster and controlling their software supply and next-gen dependency management.
Brent is the Director of Product Marketing connecting developers and DevOps communities to Sonatype Nexus tools and technologies.
Explore All Posts by Brent KostakTags
Try Nexus Repository Free Today
Sonatype Nexus Repository is the world’s most trusted artifact repository manager. Experience the difference and download Community Edition for free.