Block malicious open source at the door
Your first line of defense against modern
software supply chain attacks.
software supply chain attacks.

ENTERPRISE SECURITY
Detect
Decrease risk with early identification and warning of vulnerabilities.
Protect
Block malicious components automatically and keep your SDLC secure.
Release
Automatically release cleared components to developers and reduce friction.
Control
Establish policies and risk tolerance to determine which components are safe.

143,626 malicious packages discovered
From
AI behavioral analysis
Automated policy enforcement
Security research team
A better way to block malware

REPOSITORY PROTECTION
Avoid costly supply chain attacks

Block malicious components
Block malicious and suspicious packages until they’re confirmed or cleared by Sonatype’s security research team.
Stop vulnerabilities automatically
Prevent known vulnerabilities and harmful open source releases from downloading into your repository.
Release cleared components
Automatically release cleared components back into your development pipeline for maximum efficiency.
Debunking the Myth of Security vs. Productivity
A staggering 29% of popular projects contain vulnerabilities. Outsmart risk with Sonatype Repository Firewall.
POLICY COMPLIANCE
Automate your policy enforcement

Set policy based on risk tolerance
Decide which components are allowed into your SDLC based on risk factors like age, popularity, and licensing credentials.
Protect against the unknown
Set policy to block suspicious components, even before they are publicly disclosed as vulnerable.
Configure automatic compliance
Prevent applications from moving forward with unwanted or unapproved components.
“Sonatype Platform doesn't presume how you want to use it. It provides you with information. It provides you with data and then it gives you the tools to take that information, customize it, and do what you want with it.”
Jason Hills
Head of Application Security, TD BANK
Run products anywhere
Flexible deployment options let you run anywhere—without the operational hurdles. Deploy easily with world class support from our Technical Support team at no additional cost.
Cloud
Get started right away. Streamline your infrastructure and rapidly scale with cloud solutions hosted on AWS and managed by Sonatype.
Available for


Self Hosted
Unlock maximum flexibility. Choose to host on your own servers or in a cloud environment of choice.
Available for



Air-Gapped
Adhere to the strictest security standards for government and affiliated organizations. Sonatype offers the only software supply chain solution for air-gapped environments.
Available for



Work with the tools you already use
Universal repository support

Sonatype Nexus Repository Pro
Better together: Protect your Sonatype Nexus Repository (Pro) with Firewall.
JFrog Artifactory
Using Artifactory? No problem.Sonatype Repository Firewall supports JFrog’s Artifactory.
Firewall language support












Firewall package support








%20@2x.png?width=141&height=140&name=APT%20(debian)%20@2x.png)



“The Sonatype Platform is consistent with our gradual rise in maturity. The product brings richness from the very first use. Whether you're a beginner or a Sonatype expert, it gives you the ability to find the solutions you need. All our teams are delighted to be able to use it.”
Bruno Darras
Head of DevOps, BNP PARIBAS
Enterprise protection from attacks
Features

-
Protection from unknown vulnerabilitiesYes for npm, PyPl
-
Hosted repository protection from namespace confusion attack
-
Suspicious auto-quarantine
-
Automatic release from quarantine
-
Automated version replacement for dependencies
-
New reports and views for application security and developers
-
Improved developer experience
-
Support for artifactory enterprise
Explore the Sonatype platform