Primetals Technologies Accelerates Secure Software Releases by 10x
Manufacturing
Company Size: Enterprise
Primetals Technologies, a leader in the industrial metals sector, was burdened by time-consuming manual processes for validating open source components, which not only slowed major releases of its mission-critical automation systems but also introduced significant risk of human error. To address this, the company integrated Sonatype Lifecycle into its GitLab CI/CD pipelines, establishing a mandatory, fully automated gate while also developing custom tooling to secure its diverse technology landscape spanning Java, C++, and C#.
The Problem
Modernizing Security for Industrial Automation
As a global pioneer in engineering and plant-building for the metals industry, Primetals Technologies operates where digital innovation meets high-stakes industrial production. The software that runs these sophisticated automation systems demands the highest levels of security, safety, and reliability, often with lifetimes spanning decades. As the industry moves from isolated "network islands" to fully integrated digital plants powered by AI and ML, the need for modern software supply chain management has become a critical business imperative.
Their existing process for validating open source software (OSS) components was manual, resource-intensive, and prone to human error. Before Sonatype, developers typically upgraded third-party components for functional reasons, with security often being an afterthought. This created a high-risk environment where vulnerabilities or non-compliant licenses could inadvertently be integrated into software destined for critical industrial plants.
A single major release required hundreds of hours of manual investigation to update and check all third-party components. This not only delayed innovation but also exposed the company and its customers to potential security incidents and reputational damage. The organization needed to transition from this reactive, labor-intensive model to a proactive, automated DevSecOps workflow that could provide the confidence and control required for modern industrial software.
An Engineering-Led Approach to DevSecOps
Primetals Technologies embarked on a mission to set a new standard for secure software delivery in its field, deeply embedding Sonatype into the core of its development ecosystem. This wasn't just an implementation; it was a sophisticated, engineering-led transformation.
- Deep CI/CD Integration and Customization: The team integrated Sonatype Lifecycle directly into its GitLab pipelines. Going beyond the standard plugin, they forked and customized it to perfectly align with their internal processes, adding robust monorepo support and greater flexibility for their complex builds.
- Comprehensive Technology Coverage: They established bespoke workflows to secure their entire technology landscape. This included using the Maven plugin for Java, converting C++ packages into the Conan format for analysis, and generating CycloneDX SBOMs for legacy C# applications to be scanned by Lifecycle.
- Automated Governance: Sonatype Nexus Repository was established as the central, secure hub for all artifacts. Build pipelines were configured to push artifacts, including generated SBOMs, to Sonatype Nexus Repository only after a successful Lifecycle scan, ensuring only vetted and compliant components enter their central repository.
- SBOM Management at Scale: To meet customer needs and prepare for upcoming regulations like the EU’s Cyber Resilience Act, the team operationalized Sonatype SBOM Manager and implemented digital signatures to verify integrity and origin, providing an advanced layer of trust.
A New Benchmark for Industrial Software Security
The impact of this transformation has been profound, delivering a significant return on investment by strengthening security, improving efficiency, and fostering a culture of security ownership. What once took days now takes hours — the new automated process cuts third-party and OSS update checks by 10x.
In a significant early win, the automated pipeline caught components with critical security vulnerabilities and non-compliant licenses, preventing a potentially costly and reputation-damaging release. This single event immediately demonstrated the financial value of prevention over remediation.
The integration provides immediate, actionable feedback directly within developers' existing GitLab workflows. This shift-left approach means developers now have the security and license awareness to make smart decisions as they code. As a company in the industrial sector, not a traditional software house, Primetals Technologies' sophisticated adoption of DevSecOps is breaking new ground.
“Since introducing Sonatype, our developers receive immediate, actionable feedback directly within their existing GitLab workflows. This shift-left approach empowers them to fix issues as they code, dramatically increasing productivity by reducing the need for late-stage rework.”
Daniel Fuchshuber
Department for Digital Solutions | Primetals Technologies Austria GmbH
Primetals Technologies’ journey proves that modern DevSecOps practices are essential in every industry. By taking an engineering-led approach and customizing their tools to fit their unique needs, they have built a secure, resilient, and efficient development process. Their success in transforming from manual checks to a fully automated security gate has cultivated a powerful security-aware culture internally and positioned them as a forward-thinking leader externally. As they extend these practices to secure their AI/ML development, Primetals Technologies is building the future of secure industrial automation.