SONATYPE INTEGRATIONS
Manage SDLC Security Risk in the Tools You Already Use
Sonatype's software development lifecycle security solutions have you covered with 50+ supported languages, packages, and integrations across leading IDEs, source repositories, CI pipelines, DevSecOps tools, and ticketing systems.
Filters
Maven
Infuse your Maven builds with the most precise component intelligence and automatically fail builds based on policy violations, including violations found in transitive dependencies.
Micro Focus Fortify
Gain a 360-degree view of all your application security issues with integration to Fortify SSC and Fortify On-Demand.
Microsoft Visual Studio
Empower developers with precise component intelligence directly within Microsoft Visual Studio.
OpenShift
Use the Sonatype platform to store and manage binaries, build artifacts, and Docker containers within your OpenShift environment for enhanced application security.
PyCharm
Integrate Sonatype Nexus Repository Manager with PyCharm for streamlined appsec and faster Python development.
Red Hat Clair**
Sonatype Lifecycle integrates with Red Hat Clair to evaluate application, runtime, and OS level vulnerabilities within IQ for a single view into container risk.
sbt
Resolve dependencies and deploy your artifacts and build information to Sonatype Nexus Repository.
ServiceNow
Easily incorporate Sonatype Lifecycle’s software composition analysis and open source vulnerability scans directly into your existing ServiceNow workflows.
VS Code*
Scans JavaScript, R, Ruby, GoLang, PyPy (Python) projects for software supply chain security risks and vulnerable third-party dependencies
WebStorm
Get precise component intelligence for JavaScript/Node modules in WebStorm, the JS-focused IDE from Jetbrains.
Zscaler
Block open source malware at the edge with the Sonatype Firewall integration with Zscaler.
Sonatype Has You Covered
Comprehensive Language and Package Support Across the Ecosystem



