<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sonatype Blog &#187; jenkins</title>
	<atom:link href="http://blog.sonatype.com/people/tag/jenkins/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sonatype.com/people</link>
	<description>Sonatype is transforming software development with tools, information and services that enable organizations to build better software, faster, using open-source components.</description>
	<lastBuildDate>Thu, 16 May 2013 18:53:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Improving Software Quality Using Component Lifecycle Management with Jenkins</title>
		<link>http://blog.sonatype.com/people/2012/10/improving-software-quality-using-component-lifecycle-management-with-jenkins/</link>
		<comments>http://blog.sonatype.com/people/2012/10/improving-software-quality-using-component-lifecycle-management-with-jenkins/#comments</comments>
		<pubDate>Wed, 24 Oct 2012 12:26:05 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[Central]]></category>
		<category><![CDATA[Community]]></category>
		<category><![CDATA[Component Lifecycle Management]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Insight]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Insight for CI]]></category>
		<category><![CDATA[insight for jenkins]]></category>
		<category><![CDATA[jenkins]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=12357</guid>
		<description><![CDATA[A few weeks ago, a few of us joined the Jenkins community at the Jenkins User Conference 2012 in San Francisco. Our presentation “Improving Software Quality Using Component Lifecycle Management with Jenkins” given by Manfred Moser, was very well attended and there seemed to be a lot of interest. A video of our presentation has [...]]]></description>
				<content:encoded><![CDATA[<p>A few weeks ago, a few of us joined the Jenkins community at the Jenkins User Conference 2012 in San Francisco. Our presentation “Improving Software Quality Using Component Lifecycle Management with Jenkins” given by Manfred Moser, was very well attended and there seemed to be a lot of interest. A video of our presentation has now been posted <a href="http://confreaks.com/videos/1223-jucsf2012-improving-software-quality-using-component-lifecycle-management-with-jenkins" target="_blank">here</a> and you can download <a href="http://www.sonatype.com/people/wp-content/uploads/2012/10/JUC2012.pdf" target="_blank">the slides</a> as well.</p>

<iframe style="padding-bottom: 20px;" src="http://www.youtube.com/embed/68oWfzrDLVI" frameborder="0" width="700" height="394"></iframe>

<p>Have Jenkins (or Hudson) up and running, and want to give <a href="http://www.sonatype.com/Products/Insight-for-CI" target="_blank">Insight for CI plugin</a> a try? The plugin is available in the plugin center and easy to install and configure. &#8212; Just add a post build step and configure it to scan (e.g. your build output war file). <a href="http://www.sonatype.com/Products/Insight-for-CI/Get-The-Plugin" target="_blank">Get the plugin.</a></p>

<p>Summary and component results are completely <strong>free</strong> and will give you a very good indication of the security and license issues (or better their absence) of your software. We&#8217;ve even got you covered for manual scans – have a try with <a href="http://www.sonatype.com/Products/Insight-App-Health-Check">Insight App Health Check</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/10/improving-software-quality-using-component-lifecycle-management-with-jenkins/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Insight For CI at the Jenkins User Conference</title>
		<link>http://blog.sonatype.com/people/2012/10/insight-for-ci-at-the-jenkins-user-conference/</link>
		<comments>http://blog.sonatype.com/people/2012/10/insight-for-ci-at-the-jenkins-user-conference/#comments</comments>
		<pubDate>Tue, 09 Oct 2012 16:59:03 +0000</pubDate>
		<dc:creator>Manfred Moser</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[Hudson]]></category>
		<category><![CDATA[Insight]]></category>
		<category><![CDATA[jenkins]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=12314</guid>
		<description><![CDATA[Before JavaOne 2012 a few of us joined the Jenkins community at the Jenkins User Conference 2012 in San Francisco as Gold Sponsors. We had a great time talking to KK, Andrew and others as well as showcasing Insight For CI for Jenkins at the booth. The presentation about &#8220;Improving Software Quality Using Component Lifecycle [...]]]></description>
				<content:encoded><![CDATA[<p>Before JavaOne 2012 a few of us joined the Jenkins community at the Jenkins User Conference 2012 in San Francisco as Gold Sponsors. We had a great time talking to KK, Andrew and others as well as showcasing Insight For CI for Jenkins at the booth. The presentation about &#8220;Improving Software Quality Using Component Lifecycle Management with Jenkins&#8221; was very well attended and there seemed to be a lot of interest. In case you missed it you are however in luck &#8230;</p>

<p><span id="more-12314"></span></p>

<p>As requested by many attendees, you can download <a href="http://www.sonatype.com/people/wp-content/uploads/2012/10/JUC2012.pdf" target="_blank">the slides</a> right now. If you already have Jenkins (or Hudson) up and running, you might want to give it a try. The <a href="http://www.sonatype.com/Products/Insight-for-CI">Insight for CI plugin</a> is available in the plugin center and trivial to install and configure. Just add a post build step and configure it to scan e.g. your build output war file. The summary and component results are completely <strong>free</strong> and will give you a very good indication of the security and license issues (or better their absence) of your software. If you are using a different CI server, you should let us know so we can adjust our priorities. And we even got you covered for manual scans &#8211; have a try with <a href="http://www.sonatype.com/Products/Insight-App-Health-Check">Insight App Health Check</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/10/insight-for-ci-at-the-jenkins-user-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Time to Pay Attention to Application Security is Now</title>
		<link>http://blog.sonatype.com/people/2012/06/the-time-to-pay-attention-to-application-security-is-now/</link>
		<comments>http://blog.sonatype.com/people/2012/06/the-time-to-pay-attention-to-application-security-is-now/#comments</comments>
		<pubDate>Tue, 12 Jun 2012 12:38:47 +0000</pubDate>
		<dc:creator>Tim O'Brien</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Hudson]]></category>
		<category><![CDATA[Insight]]></category>
		<category><![CDATA[jenkins]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=11551</guid>
		<description><![CDATA[When we announced Insight for CI a few weeks ago, our message was simple &#8220;Get Proactive about Security with Insight&#8221;. A few months ago, when we introduced the Repository Health Check in Nexus Professional, we had a similar message about licensing, &#8220;Lead or Be Led to OSS Compliance&#8221;. For months we&#8217;ve been making the case [...]]]></description>
				<content:encoded><![CDATA[<p>When we announced <a href="http://www.sonatype.com/Products/Sonatype-Insight/Insight-for-CI">Insight for CI</a> a few weeks ago, our message was simple <a href="http://www.sonatype.com/people/2012/05/get-proactive-about-security-with-insight/">&#8220;Get Proactive about Security with Insight&#8221;</a>.   A few months ago, when we introduced the <a href="http://www.sonatype.com/Products/Nexus-Professional">Repository Health Check in Nexus Professional</a>, we had a similar message about licensing, <a href="http://www.sonatype.com/people/2012/04/oss-compliance-lead-or-be-led-your-choice/">&#8220;Lead or Be Led to OSS Compliance&#8221;</a>.  For months we&#8217;ve been <a href="http://www.sonatype.com/people/2012/03/were-a-java-shop-were-not-going-to-get-hacked/">making the case</a> that the time to worry about application security is now.</p>

<p>Another thing we&#8217;ve been saying is that it is our responsibility, as developers, to start paying attention to security vulnerabilities, and if we don&#8217;t take responsibility for application-level security, someone else will impose this requirement on us&#8230;</p>

<p>&#8230;and that&#8217;s exactly what&#8217;s we&#8217;re seeing both in the EU&#8217;s reform of <a href="http://ec.europa.eu/justice/data-protection/index_en.htm">Data Protection Laws</a> and as the US Congress <a href="http://thehill.com/blogs/hillicon-valley/technology/231359-overnight-tech-lawmakers-push-for-data-security-legislation-in-wake-of-linkedin-breach">responds to the latest data breach at LinkedIn</a>.  Now, who knows what sort of regulations we&#8217;re going to see in the coming months, but one thing is sure, the fact that lawmakers feel compelled to act is proof that we&#8217;re not doing enough as an industry to address security.</p>

<p>The best security is a layered approach: multiple levels of network security, security policies for production resources that limit access to individuals that need it, secure password policies, and application security.   Sonatype&#8217;s focused on that last item, application security, and our approach focuses on the components you assemble to create your applications.   If you develop software today, you understand that much of your work is spent creating applications that sit atop frameworks like Spring and Hibernate.  It isn&#8217;t enough for your own software and infrastructure to be secure.  These days, you need to account for vulnerabilities in your dependencies.</p>

<p>And, again, this isn&#8217;t operation&#8217;s responsibility.  Security is a shared responsibility across both development and operations.   This is something that developers need to take ownership of.   While we&#8217;ll probably never know how sites like LinkedIn, eHarmony, and Last.fm were compromised, there&#8217;s a good chance that some of these sites were compromised via known vulnerabilities in outdated components.  Components like Tomcat or frameworks like Struts are among the list of artifacts that have known problems.</p>

<p>Don&#8217;t get hacked because you didn&#8217;t upgrade to the latest version of Tomcat or because you happened to be using some ancient version of Spring with a known vulnerability.    If you are consuming artifacts from Central (and if you are a Java developer, you probably are), you need to start using <a href="http://www.sonatype.com/Products/Nexus-Professional">Nexus Professional</a> to keep track of your dependencies.   If you are using Hudson or Jenkins, take some time to evaluate <a href="http://www.sonatype.com/Products/Sonatype-Insight/Insight-for-CI">Insight for CI</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/06/the-time-to-pay-attention-to-application-security-is-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Webinar Replay Now Available: Insight for CI Demo</title>
		<link>http://blog.sonatype.com/people/2012/05/webinar-replay-now-available-insight-for-ci-demo/</link>
		<comments>http://blog.sonatype.com/people/2012/05/webinar-replay-now-available-insight-for-ci-demo/#comments</comments>
		<pubDate>Thu, 31 May 2012 15:03:57 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[Hudson]]></category>
		<category><![CDATA[Insight]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[continuous integration]]></category>
		<category><![CDATA[jenkins]]></category>
		<category><![CDATA[OSS security]]></category>
		<category><![CDATA[Sonatype webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=11505</guid>
		<description><![CDATA[A big thanks to all of you who registered and attended our Insight for CI Demo last week. We had a great turnout and a lot of fantastic questions! If you didn’t have a chance to register, that doesn’t mean you have to miss out. The replay is now available. Request the webinar recording here. [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.sonatype.com/people/2012/05/new-webinar-gain-visibility-control-at-build-time-with-insight-for-ci/blog_header_ciwebinarlaunch-3/" rel="attachment wp-att-11398"><img class="aligncenter size-full wp-image-11398" title="blog_header_CIWebinarLaunch" src="http://www.sonatype.com/people/wp-content/uploads/2012/05/blog_header_CIWebinarLaunch2.png" alt="" width="700" height="200" /></a></p>

<p>A big thanks to all of you who registered and attended our Insight for CI Demo last week. We had a great turnout and a lot of fantastic questions! If you didn’t have a chance to register, that doesn’t mean you have to miss out. The replay is now available.</p>

<p><a href="http://sonatype.com/Request/Webinar/Insight-for-CI-Demo-Gain-Visibility-Control-At-Build-Time?webinar=CILaunchReplay_Blog&amp;utm_source=Blog&amp;utm_medium=Post&amp;utm_campaign=CILaunchReplay" target="_blank"><strong>Request the webinar recording here.</strong> </a></p>

<p>Ready to try Insight for CI for yourself? Let us help you <a href="http://sonatype.com/Products/Sonatype-Insight/Insight-for-CI" target="_blank"><strong>get started</strong></a>.</p>

<p>Thank you!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/05/webinar-replay-now-available-insight-for-ci-demo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Get proactive about Security with Insight</title>
		<link>http://blog.sonatype.com/people/2012/05/get-proactive-about-security-with-insight/</link>
		<comments>http://blog.sonatype.com/people/2012/05/get-proactive-about-security-with-insight/#comments</comments>
		<pubDate>Fri, 25 May 2012 14:47:48 +0000</pubDate>
		<dc:creator>Tim O'Brien</dc:creator>
				<category><![CDATA[Hudson]]></category>
		<category><![CDATA[Insight]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[jenkins]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=11446</guid>
		<description><![CDATA[There&#8217;s a shift in the way organizations are thinking about security, and This article in Infoworld &#8220;IBM: Security execs move more toward active risk management&#8221; is exactly what we&#8217;ve been talking about. Here&#8217;s the quote that stood out: &#8220;Nearly two-thirds of security leaders say their senior executives are paying more attention to security today than [...]]]></description>
				<content:encoded><![CDATA[<p>There&#8217;s a shift in the way organizations are thinking about security, and <a href="http://www.infoworld.com/d/security/ibm-security-execs-move-more-toward-active-risk-management-192465">This article in Infoworld &#8220;IBM: Security execs move more toward active risk management&#8221;</a> is exactly what we&#8217;ve been talking about.   Here&#8217;s the quote that stood out:</p>

<blockquote style="padding-left: 30px; padding-right: 30px; padding-bottom: 20px; font-size: 90%; font-family: courier; ">&#8220;Nearly two-thirds of security leaders say their senior executives are paying more attention to security today than they were two years ago, <b>due in large part to media attention.</b>&#8221; and &#8220;60 percent of the advanced organizations named security as a regular boardroom topic, compared to only 22 percent of the least advanced organizations&#8221;</blockquote>

<p>Instead of simple three-tiered applications following a standard Apache -> Tomcat -> RDBMS pattern, today&#8217;s scaleable applications involve a portfolio of technologies: Redis, Hadoop, real-time BI systems, integration with 3rd party APIs, Node.js, with more and more companies adopting a portfolio of technologies.   It is becoming increasingly difficult to draw a line around a particular application and evaluate security vulnerabilities in isolation.</p>

<p>Today, you need to have your security group sitting next to you evaluating a complex application as it evolves&#8230;.  but, back to the article, it isn&#8217;t just the evolution of technology that is making security a focus for business, it is a series of high-profile, embarrassing data breaches.  A CEO that wouldn&#8217;t have thought very much about security technology a few years ago, sees what happens to a Stratfor or Global Payments and they understand the risks.  Data security is front and center in the news, and a data breach can be a business-ending event.</p>

<p>So get out in front the problem. Start tracking your application dependencies and identify known vulnerabilities with Insight.</p>

<p><center><img src="http://www.sonatype.com/people/wp-content/uploads/2012/05/security-summary.png" alt="" title="security-summary" width="480" height="221" style="border: 1px solid black;"/></center></p>

<p>When we launched Nexus Professional and integrated Sonatype Insight information we gave you the ability to keep track of your overall exposure to security vulnerabilities.   Your IT organization gained a window into the intersection of known vulnerabilities with the artifacts you download from Central.  That was a good start, but the real benefit is Insight for CI.  We launched Insight for CI this week, and it&#8217;s the tool you&#8217;ll want to use to address security vulnerabilities in specific products.   If it is your responsibility to keep up with security, one of the easiest ways to take a more proactive approach is to start using Insight for CI to track your application&#8217;s dependencies.</p>

<p><a href="http://www.sonatype.com/Request/Plugin/Register-Interest-for-Insight-for-CI">Click here</a> to get started with Insight for CI.  It works with either Hudson or Jenkins, and it covers both license and security information.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/05/get-proactive-about-security-with-insight/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
