SONATYPE INTEGRATIONS

Manage SDLC Security Risk in the Tools You Already Use

Sonatype's software development lifecycle security solutions have you covered with 50+ supported languages, packages, and integrations across leading IDEs, source repositories, CI pipelines, DevSecOps tools, and ticketing systems.

Maven

Infuse your Maven builds with the most precise component intelligence and automatically fail builds based on policy violations, including violations found in transitive dependencies.

See Integration Details

Micro Focus Fortify

Gain a 360-degree view of all your application security issues with integration to Fortify SSC and Fortify On-Demand.

See Integration Details

Microsoft Visual Studio

Empower developers with precise component intelligence directly within Microsoft Visual Studio.

See Integration Details

OpenShift

Use the Sonatype platform to store and manage binaries, build artifacts, and Docker containers within your OpenShift environment for enhanced application security.

See Integration Details

PyCharm

Integrate Sonatype Nexus Repository Manager with PyCharm for streamlined appsec and faster Python development.

See Integration Details

Red Hat Clair**

Sonatype Lifecycle integrates with Red Hat Clair to evaluate application, runtime, and OS level vulnerabilities within IQ for a single view into container risk.

See Integration Details

sbt

Resolve dependencies and deploy your artifacts and build information to Sonatype Nexus Repository.

See Integration Details

ServiceNow

Easily incorporate Sonatype Lifecycle’s software composition analysis and open source vulnerability scans directly into your existing ServiceNow workflows.

See Integration Details

VS Code*

Scans JavaScript, R, Ruby, GoLang, PyPy (Python) projects for software supply chain security risks and vulnerable third-party dependencies

See Integration Details

WebStorm

Get precise component intelligence for JavaScript/Node modules in WebStorm, the JS-focused IDE from Jetbrains.

See Integration Details

Zscaler

Block open source malware at the edge with the Sonatype Firewall integration with Zscaler.

See Integration Details