product-logos-firewall
nexus
firewall

Your first line of defense against modern software supply chain attacks.

Home-Firewall-V2
Home-Firewall-V2

108,232 malicious packages discovered

From
AI behavioral analysis
Automated policy enforcement
Security research team

REPOSITORY PROTECTION

Avoid costly supply chain attacks

FIREWALL-REPO-PROTECTION-UI_wTooltip

Block malicious components

Block malicious and suspicious packages until they’re confirmed or cleared by Sonatype’s security research team.

Stop vulnerabilities automatically

Prevent known vulnerabilities and harmful open source releases from downloading into your repository.

Release cleared components

Automatically release cleared components back into your development pipeline for maximum efficiency.
“Sonatype provided the tools and support we needed to streamline due diligence, reduce risk, and move forward with confidence.”
John Goodson
Senior VP of Products, Progress

POLICY COMPLIANCE

Automate your policy enforcement

FIREWALL-AUTOMATE-UI_wTooltip

Set policy based on risk tolerance

Decide which components are allowed into your SDLC based on risk factors like age, popularity, and licensing credentials.

Protect against the unknown

Set policy to block suspicious components, even before they are publicly disclosed as vulnerable.

Configure automatic compliance

Prevent applications from moving forward with unwanted or unapproved components.

“Nexus Platform doesn't presume how you want to use it. It provides you with information. It provides you with data and then it gives you the tools to take that information, customize it, and do what you want with it.”
Jason Hills
Head of Application Security, TD BANK

Run products anywhere

Flexible deployment options let you run anywhere—without the operational hurdles. Deploy easily with world class support from our Technical Support team at no additional cost.

Cloud

Get started right away. Streamline your infrastructure and rapidly scale with cloud solutions hosted on AWS and managed by Sonatype.
Available for
NexusFirewall_Icon@3x NexusLifecycle_Icon (1) SonatypeLift_Icon_color

Self Hosted

Unlock maximum flexibility. Choose to host on your own servers or in a cloud environment of choice.
Available for
NexusFirewall_Icon@3x NexusRepo_Icon@2x NexusLifecycle_Icon (1)

Disconnected

Adhere to the strictest security standards for government and affiliated organizations. Sonatype offers the only software supply chain solution for air-gapped environments.
Available for
NexusFirewall_Icon@3x NexusRepo_Icon@2x NexusLifecycle_Icon (1)

Work with the tools you already use

Universal repository support

Nexus Repository Pro
Better together: Protect your Nexus Repository (Pro) with Firewall.
JFrog Artifactory
Using Artifactory? No problem.
Nexus Firewall supports JFrog’s Artifactory.

Firewall language support

C
C++
Go
Gosu
Java
PHP
Python
R
Ruby
Scala
Swift
Visual Basic

Firewall package support

Maven
npm
Docker
PyPi
Nuget
Yum
Go
Rubygems
Apt
Helm
gitlfs
Conan
“The Nexus Platform is consistent with our gradual rise in maturity. The product brings richness from the very first use. Whether you're a beginner or a Nexus expert, it gives you the ability to find the solutions you need. All our teams are delighted to be able to use it.”
Bruno Darras
Head of DevOps, BNP PARIBAS

Enterprise protection from attacks

Features
nexus-firewall-logo
  • Protection from unknown vulnerabilities
    Yes for npm, PyPl
  • Hosted repository protection from namespace confusion attack
  • Suspicious auto-quarantine
  • Automatic release from quarantine
  • Automated version replacement for dependencies
  • New reports and views for application security and developers
  • Improved developer experience
  • Support for artifactory enterprise

Block malicious open source at the door