Sonatype Introduces Next Generation Dependency Management | Press Release

Press Releases

The latest scoop on Sonatype.

Sonatype Overhauls JavaScript Scanning; Provides npm Automated Pull Requests and More Free Developer Tools

Enhanced solutions take advantage of new algorithms to better identify security vulnerabilities in open source npm packages

Fulton, MD – March 3, 2020 -- Sonatype, the company that scales DevOps through open source governance and software supply chain automation, announced an enhanced suite of JavaScript intelligence capabilities that provides developers with improved accuracy, increased policy control, and faster remediation of open source vulnerabilities across the entire software development lifecycle (SDLC). 

Sonatype Streamlines Deployment for Millions of Developers Using Kubernetes, Adds Native Helm Support to Nexus Repository

Fulton, MD – February 24, 2020 -- Sonatype, the company that scales DevOps through open source governance and software supply chain automation, now includes native support for Helm in Nexus Repository (NXRM). Additional support for developers using Helm Chart Repositories, and by extension Kubernetes, is part of the company’s commitment to strengthening container-based development and ensuring NXRM always enables users to universally manage software libraries and build artifacts.

Eficode and Sonatype Partner to Secure the Software Supply Chain for Modern Enterprise Organisations

With the Sonatype Nexus Platform, Eficode helps customers understand the importance of shifting left and automating open source security across the DevOps pipeline

Helsinki, Finland, Nov. 27, 2019 -- Today, Eficode, the European leader in DevOps that is designing, optimising, and managing today’s evolving software development lifecycle processes with its DevOps Platform Eficode ROOT, announced a partnership with Sonatype, the inventors of software supply chain automation, to bring open source governance to its rapidly-growing customer base. 

Sonatype Fully Automates Container Security

Nexus Lifecycle delivers open API for best-in-class policy control for all container layers

Fulton, MD – Monday, Nov. 25 2019 - Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today announced an open API that makes it easy for third-party container scanners to integrate with Nexus Lifecycle and equip engineering teams with a holistic solution to automatically and accurately control risk related to containers traversing the modern software development lifecycle (SDLC).

Vista Equity Partners Acquires Majority Interest in DevOps Leader Sonatype

Partnership to Accelerate Global Growth and Innovation for Automating Open Source Governance and Software Supply Chain Hygiene

FULTON, MD - November 18, 2019 - Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today announced it has signed a definitive agreement to receive a majority investment from Vista Equity Partners (“Vista”), a leading investment firm focused on empowering and growing enterprise software, data and technology-enabled companies that are reinventing industries and catalyzing change. The partnership with Vista will allow Sonatype to further fast-track growth and enhance its Nexus product portfolio. Several of Sonatype’s existing investors will retain a stake in the company.

Sonatype Delivers Premium Open Source Controls to GitHub Users

New Integrations Deliver Enterprise-Grade Open Source Governance and Dependency Management to Millions of GitHub Developers

San Francisco - GitHub Universe – Tuesday, Nov. 12, 2019Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today announced new integrations that strengthen GitHub with premium open source governance and dependency management controls.

Sonatype Partners with All Day DevOps to help Educate More Than 36,000 IT Professionals

The 2019 event has garnered the largest audience yet to participate in 24 hour conference starting at 3 am ET on November 6 

McLean, Va -- Nov. 5, 2019 - Sonatype, the company that scales DevOps through open source governance and software supply chain automation, has partnered with All Day DevOps, the largest conference in the world dedicated to sharing DevOps best practices, on its fourth annual event, streams live for 24 hours starting at 8:00 am GMT on Nov 6, 2019 (3:00 am ET). 

Sonatype’s Nexus Repository Manager Expands OSS Coverage, Sees 40% YoY User Growth

Support for CocoaPods, Conda and APT accelerates development and enables improved binary management

Fulton, MDFriday, Oct. 25, 2019Sonatype, the inventors of software supply chain automation, today announced its popular Nexus Repository Manager (NXRM) now includes support for CocoaPods, Conda and APT (Advanced Package Tool) proxy repositories. This additional coverage is part of a concerted effort to accelerate development support of new formats, ensuring NXRM continues to enable users to universally manage software libraries and build artifacts. The Nexus Platform now supports 42 languages and packages. 

This news also comes on the heels of 40% year-over-year growth in number of users across NXRM professional and OSS versions, highlighting its position as the defacto standard within DevOps toolchains worldwide. 

Sonatype Delivers First of its Kind, Automated Malware Prevention for Open Source Libraries

Nexus Intelligence research engine now automatically detects counterfeit and malicious code injections into open source software supply chains

Fulton, MD – Tuesday, Sept. 24, 2019 –Today, Sonatype, the inventors of software supply chain automation, announced it has developed new early warning capabilities to detect malicious releases of open source components, known as “counterfeit components,” and block their use within modern software factories. The patent-pending technology, part of the next generation of Sonatype’s Nexus Intelligence, monitors millions of open source projects in real-time to identify abnormal development behavior and suspicious patterns as new component versions are released.

Micro Focus Bolsters Strategic Partnership with Sonatype, Brings Best-in-Class Open Source Security to All Fortify Customers

New Joint Solution Delivers a Single, Fully Integrated Application Security Platform for Managing Open Source Risk and Vulnerabilities for Fortify on Demand and Fortify On-Premise

SANTA CLARA, CA -- Sept. 9, 2019 – Micro Focus (LSE: MCRO; NYSE: MFGP) today announced an expanded strategic partnership with Sonatype to provide the combined power of Micro Focus' application security as a service, Fortify, and Sonatype's leading automated open source governance solution, to even more customers. The new relationship, which promotes Sonatype as Fortify's preferred Software Composition Analysis (SCA) partner, delivers the advantages of a single, fully integrated application security platform, without compromising depth and capability in managing open source risk and vulnerabilities.