<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sonatype Blog &#187; Nexus</title>
	<atom:link href="http://blog.sonatype.com/people/tag/nexus/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sonatype.com/people</link>
	<description>Sonatype is transforming software development with tools, information and services that enable organizations to build better software, faster, using open-source components.</description>
	<lastBuildDate>Wed, 19 Jun 2013 19:07:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>How Will you Manage the New Addition of A9 to the OWASP Top 10 List?</title>
		<link>http://blog.sonatype.com/people/2013/06/a9_nexusclm/</link>
		<comments>http://blog.sonatype.com/people/2013/06/a9_nexusclm/#comments</comments>
		<pubDate>Tue, 18 Jun 2013 15:30:05 +0000</pubDate>
		<dc:creator>Jessica Dodson</dc:creator>
				<category><![CDATA[Central]]></category>
		<category><![CDATA[CLM]]></category>
		<category><![CDATA[Component Lifecycle Management]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[A9]]></category>
		<category><![CDATA[Nexus CLM]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[repository management]]></category>
		<category><![CDATA[The Central Repository]]></category>

		<guid isPermaLink="false">http://blog.sonatype.com/people/?p=13520</guid>
		<description><![CDATA[It’s fair to say we were excited back in May when the OWASP community proposed A9 “ Using Components with Known Vulnerabilities” as a top 10 open source security risk – so now it’s official, component vulnerabilities are considered a critical web security flaw. But why has this addition warranted its own category, formerly classified [...]]]></description>
				<content:encoded><![CDATA[<p>It’s fair to say we were excited back in May when the <a href="http://blog.sonatype.com/people/2013/05/owasp-recognizes-component-security/">OWASP community <i>proposed</i> A9</a> “ Using Components with Known Vulnerabilities” as a top 10 open source security risk – so now it’s official, <a href="http://www.networkworld.com/community/node/83218">component vulnerabilities are considered a critical web security flaw</a>. But why has this addition warranted its own category, formerly classified under ‘Security Misconfiguration’? Has the problem truly compounded that much in the last 3 years that now, component vulnerabilities need to be on a watch list? Well simply put, YES. According to the largest open source component repository, The Central Repository, <a href="http://www.sonatype.com/clm/the-component-revolution">component downloads</a> have grown from 1.5 billion requests in 2008 to over 8 billion requests in 2012. Now that’s a quite growth pattern.</p>

<p>Today the use of 3<sup>rd</sup> party frameworks and libraries in application development is an everyday practice, but unfortunately proper security policies aren’t. So how do you know what security risks really exist? As OWASP points out, this isn’t an easy question to answer “<i>most development teams don’t focus on ensuring their components/libraries are up to date. In many cases, the developers don’t even know all the components they are using, never mind their versions. Component dependencies make things even worse</i>.”</p>

<p>So how do you manage this problem effectively? Well our CEO says, securing the software lifecycle requires both humans and machines. Humans define the security and license policies, machines automate these policies and humans manage the expectations. With these policies and enforcement in place (right in the developer environment) the possible vulnerabilities are detected earlier in the software development lifecycle and developers have the option to remediate these risks and use other components that meet their organization’s security policies.</p>

<p>A perfect use case for remediating possible security threats during the development lifecycle happens after the build promotion and staging. You can define policies based on security, licensing  and quality standards. If the build doesn’t meet the set policies, the build can be stopped and the developer can be notified before the release workflow is allowed to continue. You can see this example in action in an upcoming webinar, ‘<a href="https://sonatype.webex.com/ec0606l/eventcenter/enroll/register.do?siteurl=sonatype&amp;formId=0&amp;formType=0&amp;loadFlag=1&amp;confId=1230997723&amp;theAction=landingfrommail&amp;confViewID=1230997723&amp;&amp;email=hthimaya%40cisco.com&amp;encryptTicket=4ba1437ad3f59f70cc8337f4f538c63f&amp;&amp;encryptTicketRegister=4ba1437ad3f59f70cc8337f4f538c63f&amp;siteurl=sonatype&amp;rnd=0.472651078270819">Nexus Pro: Fully Automate Your Build Promotion’</a> as a way to start thinking about the value of managing components against your open source security policies.</p>

<p>For those concerned about the recent OWASP A9 announcement (which should be all of you), watching this webinar is a great entry point into defining a larger vision for lifecycle component management. Don’t wait to your CISO comes to you with a question about where and how you’re using 3<sup>rd</sup> party components with known vulnerabilities, start incorporating policy enforcement during the development lifecycle now.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/06/a9_nexusclm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join Us: Nexus Office Hours &#8212; This Friday!</title>
		<link>http://blog.sonatype.com/people/2013/04/join-us-nexus-office-hours-this-friday/</link>
		<comments>http://blog.sonatype.com/people/2013/04/join-us-nexus-office-hours-this-friday/#comments</comments>
		<pubDate>Tue, 23 Apr 2013 12:03:22 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Nexus Office Hours]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13253</guid>
		<description><![CDATA[Wondering what&#8217;s new in Nexus? Just ask the experts. We&#8217;re hosting another Nexus Office Hours this Friday, on Google+ Hangout On Air. Our Nexus experts Brian Fox, Manfred Moser and Rich Seddon will demo the latest in Nexus and dedicate most of the hour to Q&#38;A time with you! How to join: No registration required, [...]]]></description>
				<content:encoded><![CDATA[<h3><strong></strong><a href="http://www.sonatype.com/people/2013/04/join-us-nexus-office-hours-this-friday/screen-shot-2013-04-23-at-6-54-44-am-2/" rel="attachment wp-att-13265"><img class="aligncenter size-full wp-image-13265" title="Screen shot 2013-04-23 at 6.54.44 AM" src="http://www.sonatype.com/people/wp-content/uploads/2013/04/Screen-shot-2013-04-23-at-6.54.44-AM1.png" alt="" width="696" height="235" /></a></h3>

<h3>Wondering what&#8217;s new in Nexus? Just ask the experts.</h3>

<p>We&#8217;re hosting another <a href="https://plus.google.com/u/0/b/117596333621717490325/events/c0rgc97eam66k7hpqss4q87bn28" target="_blank">Nexus Office Hours</a> this Friday, on Google+ Hangout On Air. Our <a href="http://www.sonatype.com/Products/Nexus-Professional" target="_blank">Nexus</a> experts Brian Fox, Manfred Moser and Rich Seddon will demo the latest in Nexus and dedicate most of the hour to Q&amp;A time with you!</p>

<p><strong>How to join:</strong> No registration required, just <a href="https://plus.google.com/u/0/b/117596333621717490325/events/c0rgc97eam66k7hpqss4q87bn28" target="_blank">RSVP on Google+</a>, and the event will appear in your calendar. You can join through your calendar invite or by returning to the event page at the start of the hangout. Be sure to bring your Nexus questions with you. If you can&#8217;t make it &#8212; be sure to leave your questions on the event page in the comments section and we&#8217;ll be sure to answer them during the session. That way you can tune into the recording later, and get your answers!</p>

<p>*Interested in joining our panel that day in the video conference? Sign up for one of the spots on our panel, by leaving us a comment on the event page and we&#8217;ll invite you in before we go live. Space is limited, so be sure to sign up early!</p>

<p>Please feel free to pass along this invite to your friends and colleagues.</p>

<p><a href="https://plus.google.com/u/0/b/117596333621717490325/events/c0rgc97eam66k7hpqss4q87bn28" target="_blank"><strong>RSVP</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/04/join-us-nexus-office-hours-this-friday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When Nexus Alone Is Not Enough &#8211; Webinar Recording Now Available!</title>
		<link>http://blog.sonatype.com/people/2013/04/when-nexus-alone-is-not-enough-webinar-recording-now-available/</link>
		<comments>http://blog.sonatype.com/people/2013/04/when-nexus-alone-is-not-enough-webinar-recording-now-available/#comments</comments>
		<pubDate>Fri, 19 Apr 2013 21:35:16 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[CLM]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[Component Lifecycle Management]]></category>
		<category><![CDATA[Sonatype webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13226</guid>
		<description><![CDATA[A big thanks goes out to everyone who was able to make it to our webinar yesterday. We appreciated all of your time, attention and great questions. If you weren&#8217;t able to make it, no worries &#8212; the recording is now available here. Please feel free to share this with your colleagues who are interested [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: left;">A big thanks goes out to everyone who was able to make it to our webinar yesterday. We appreciated all of your time, attention and great questions. If you weren&#8217;t able to make it, no worries &#8212; the recording is now available <a href="https://www.youtube.com/watch?v=DCPra4SnjJ8" target="_blank">here.</a></p>

<p style="text-align: left;">Please feel free to share this with your colleagues who are interested in learning how to get the most out of <a href="http://www.sonatype.com/Products/Nexus-Professional" target="_blank">Nexus</a>.</p>

<p style="text-align: left;">Have a great weekend everyone!</p>

<h4><a href="https://www.youtube.com/watch?v=DCPra4SnjJ8" target="_blank"><strong>Watch the replay.</strong></a></h4>

<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/04/when-nexus-alone-is-not-enough-webinar-recording-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March Nexus Office Hours &#8211; Recording Now Available</title>
		<link>http://blog.sonatype.com/people/2013/03/march-nexus-office-hours-recording-now-available/</link>
		<comments>http://blog.sonatype.com/people/2013/03/march-nexus-office-hours-recording-now-available/#comments</comments>
		<pubDate>Fri, 29 Mar 2013 11:59:48 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[Nexus Office Hours]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13092</guid>
		<description><![CDATA[Thank you so much to everyone who turned out for our first Nexus Office Hours session last week! We hope you enjoyed it and learned a lot. We appreciated all of your time, questions, attention and feedback. A big thanks also goes out to Max for being our guest panelist and for bringing such great [...]]]></description>
				<content:encoded><![CDATA[<p>Thank you so much to everyone who turned out for our first <a href="https://plus.google.com/u/0/b/117596333621717490325/events/cstc3ac2ijh0a97s9snqqjrpsrg" target="_blank">Nexus Office Hours</a> session last week! We hope you enjoyed it and learned a lot. We appreciated all of your time, questions, attention and feedback. A big thanks also goes out to Max for being our guest panelist and for bringing such great questions!</p>

<p>If you missed the live broadcast, the recording is now available <a href="https://plus.google.com/u/0/b/117596333621717490325/events/cstc3ac2ijh0a97s9snqqjrpsrg" target="_blank">here</a>.</p>

<p>Interested in checking out our next session? Moving forward, Nexus Office Hours will be held the last Friday of every month. Join us and be sure to bring any general repository management or specific Nexus questions you may have, since we&#8217;ll be dedicating most of the hour to your live Q&amp;A.</p>

<p>Join us for our <a href="https://plus.google.com/u/0/b/117596333621717490325/events/c0rgc97eam66k7hpqss4q87bn28" target="_blank">April Nexus Office Hours</a> on Friday, April 26 from 1PM-2PM EDT (GMT-0400). <a href="https://plus.google.com/u/0/b/117596333621717490325/events/c0rgc97eam66k7hpqss4q87bn28" target="_blank">RSVP here.</a><strong>
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/03/march-nexus-office-hours-recording-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Webinar &#8211; When Nexus is Not Enough: Manage Your Components Beyond the Repository</title>
		<link>http://blog.sonatype.com/people/2013/03/new-webinar-when-nexus-is-not-enough-manage-your-components-beyond-the-repository/</link>
		<comments>http://blog.sonatype.com/people/2013/03/new-webinar-when-nexus-is-not-enough-manage-your-components-beyond-the-repository/#comments</comments>
		<pubDate>Wed, 27 Mar 2013 14:27:41 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[CLM]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[Sonatype webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13075</guid>
		<description><![CDATA[At the end of April we&#8217;ll be announcing a whole new product line, Sonatype CLM, to help development groups make the best component choices. CLM (Component Lifecycle Management) extends your investment in Nexus to help inform and manage the entire software lifecycle &#8212; from design to production. We want to give you a sneak preview. [...]]]></description>
				<content:encoded><![CDATA[<p>At the end of April we&#8217;ll be announcing a whole new product line, Sonatype CLM, to help development groups make the best component choices.<a title="CLM Overview" href="http://www.sonatype.com/Products/Why-CLM/Component-Lifecycle-Management" target="_blank"> CLM (Component Lifecycle Management)</a> extends your investment in Nexus to help inform and manage the entire software lifecycle &#8212; from design to production.</p>

<p>We want to give you a sneak preview. On Thursday, April 18, 2013 from 11:00AM-11:30AM EDT (GMT-0400), Brian Fox will demo Sonatype CLM, and show you how it will help you develop faster, and still meet your company&#8217;s requirements for security and licensing. Plus, we&#8217;ll provide some tips on how you can take advantage of Nexus-only features like procurement and staging.</p>

<p>If you <a title="Webinar Registration" href="http://goo.gl/xZco4" target="_blank">register</a>, you&#8217;ll also receive access to the recording after the event. So if something comes up and you can&#8217;t make it, you won&#8217;t miss out.</p>

<h4><a title="Webinar Registration" href="http://goo.gl/xZco4" target="_blank"><strong>Reserve Your Seat</strong></a></h4>

<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/03/new-webinar-when-nexus-is-not-enough-manage-your-components-beyond-the-repository/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join Us: Nexus Office Hours &#8211; Friday, March 22, 2013 1PM-2PM EDT</title>
		<link>http://blog.sonatype.com/people/2013/03/join-us-nexus-office-hours-friday-march-22-2013-1pm-2pm-edt/</link>
		<comments>http://blog.sonatype.com/people/2013/03/join-us-nexus-office-hours-friday-march-22-2013-1pm-2pm-edt/#comments</comments>
		<pubDate>Mon, 11 Mar 2013 15:36:40 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[Nexus Office Hours]]></category>
		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13015</guid>
		<description><![CDATA[Wondering what&#8217;s new in Nexus? Wishing you had a chance to ask some of our Nexus experts about Nexus best practices? Here&#8217;s your chance. We&#8217;re pleased to announce that Sonatype will be hosting Nexus Office Hours each month starting in March! Our Nexus experts Brian Fox, Manfred Moser and Rich Seddon will demo the latest [...]]]></description>
				<content:encoded><![CDATA[<p>Wondering what&#8217;s new in Nexus? Wishing you had a chance to ask some of our Nexus experts about Nexus best practices? Here&#8217;s your chance.</p>

<p>We&#8217;re pleased to announce that Sonatype will be hosting <a href="https://plus.google.com/u/0/b/117596333621717490325/events/cstc3ac2ijh0a97s9snqqjrpsrg" target="_blank">Nexus Office Hours</a> each month starting in March! Our Nexus experts Brian Fox, Manfred Moser and Rich Seddon will demo the latest Nexus tips &amp; tricks and will take real-time questions from you!</p>

<p><strong>When:</strong> Friday, March 22, 2013 &#8211; 1:00-2:00PM EDT (GMT-0400)</p>

<p><strong>Where:</strong> In a Google+ Hangout On Air! Once we begin, our hangout will broadcast live to the <a href="https://plus.google.com/u/0/b/117596333621717490325/events/cstc3ac2ijh0a97s9snqqjrpsrg" target="_blank">Nexus Office Hours event page </a>on Google+, as well as our Sonatype YouTube channel.</p>

<p><strong>How:</strong> Be sure to <a href="https://plus.google.com/u/0/b/117596333621717490325/events/cstc3ac2ijh0a97s9snqqjrpsrg" target="_blank">RSVP &#8216;Yes&#8217;</a> on the Nexus Office Hours event page, and this event will be automatically saved to your Gmail calendar and you will receive a reminder just before we start the hangout. Not on Google+? No worries, you can still view the broadcast on the event page or the Sonatype YouTube channel when the hangout begins.</p>

<p>We will be taking real-time questions submitted on the Nexus Office Hours event page, Twitter (please use hashtag #nexusofficehours) and on our YouTube page in the comments section of the broadcast.</p>

<p>**If you&#8217;d like to join our panel that day in the hangout, please leave us a comment on this page and the first 6 people will be invited in as the session starts. This event will be recorded and saved to Google+ as well as our YouTube channel.</p>

<p><strong><a href="https://plus.google.com/u/0/b/117596333621717490325/events/cstc3ac2ijh0a97s9snqqjrpsrg" target="_blank">RSVP Now</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/03/join-us-nexus-office-hours-friday-march-22-2013-1pm-2pm-edt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure Central Connectivity – Artifactory &amp; Archiva Now Supported</title>
		<link>http://blog.sonatype.com/people/2013/01/secure-central-connectivity-artifactory-archiva-now-supported/</link>
		<comments>http://blog.sonatype.com/people/2013/01/secure-central-connectivity-artifactory-archiva-now-supported/#comments</comments>
		<pubDate>Tue, 15 Jan 2013 16:20:31 +0000</pubDate>
		<dc:creator>Mark Troester</dc:creator>
				<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Archiva]]></category>
		<category><![CDATA[artifactory]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=12666</guid>
		<description><![CDATA[Keeping with our desire to protect the entire Central Repository ecosystem, SSL connectivity to the Central Repository from JFrog Artifactory or Apache Archiva is now available. We’re using SSL because it is the standard mechanism for protecting web traffic – across the spectrum of Ecommerce, banking, health care, and so on. Providing SSL support for [...]]]></description>
				<content:encoded><![CDATA[<p>Keeping with our desire to protect the entire Central Repository ecosystem, SSL connectivity to the Central Repository from JFrog Artifactory or Apache Archiva is now available.</p>

<p>We’re using SSL because it is the standard mechanism for protecting web traffic – across the spectrum of Ecommerce, banking, health care, and so on. Providing SSL support for Central means that your components are no longer susceptible to man-in-the-middle attacks that could compromise the component. SSL also eliminates the potential for a hacker to gain visibility into your organization by tracking the components that you download for your development initiatives.</p>

<p>Given the tremendous growth of Central, and to better protect applications that are now largely built from OSS components, we’re making SSL connectivity to Central available to anyone regardless of their repository manager. SSL is now the default connectivity option for Nexus Pro users. SSL is available for other repository managers, such as Nexus OSS &amp; Artifactory or Archiva, for a $10 donation that will be used to support open source foundations such as Apache and Eclipse.</p>

<p>After you register and make the $10 donation, a token will be provided that your organization can use to secure access to Central.</p>

<p>If you are an Artifactory, Archiva or Nexus OSS user, <a href="http://www.sonatype.com/Products/Secure-Access-to-Central">you can get SSL access here</a>.</p>

<p>Archiva 1.4+ is required.</p>

<p>Artifactory 2.6.5 is required.</p>

<p>If you are an existing Nexus Pro customer, you can download the latest release <a href="https://support.sonatype.com/entries/20673111-how-do-i-download-nexus-professional?__utma=84359451.588364643.1347459146.1357935480.1357942625.356&amp;__utmb=84359451.33.8.1357944103980&amp;__utmc=84359451&amp;__utmx=-&amp;__utmz=84359451.1355152121.296.7.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=(not%20provided)&amp;__utmv=-&amp;__utmk=155489970">from the support page</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/01/secure-central-connectivity-artifactory-archiva-now-supported/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Now Available: SSL Connectivity to Central</title>
		<link>http://blog.sonatype.com/people/2012/10/now-available-ssl-connectivity-to-central/</link>
		<comments>http://blog.sonatype.com/people/2012/10/now-available-ssl-connectivity-to-central/#comments</comments>
		<pubDate>Thu, 25 Oct 2012 15:15:33 +0000</pubDate>
		<dc:creator>Brian Fox</dc:creator>
				<category><![CDATA[Central]]></category>
		<category><![CDATA[Community]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Archiva]]></category>
		<category><![CDATA[artifactory]]></category>
		<category><![CDATA[central]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=12387</guid>
		<description><![CDATA[We know how components from the Central Repository have become critical to your development efforts. We also know that you need to trust those components. Part of that trust is knowing that hackers don&#8217;t have visibility into the components you download or that they compromise components using a man-in-the middle or Cross Build Injection (XBI) [...]]]></description>
				<content:encoded><![CDATA[<p>We know how components from the Central Repository have become critical to your development efforts. We also know that you need to trust those components. Part of that trust is knowing that hackers don&#8217;t have visibility into the components you download or that they compromise components using a man-in-the middle or <a href="http://branchandbound.net/blog/security/2012/10/cross-build-injection-in-action/">Cross Build Injection</a> (XBI) attack.</p>

<p>We&#8217;re making SSL connectivity to Central available to anyone that downloads open source components regardless of the repository manager. Given the tremendous growth of Central, and the fact that modern applications are largely built from OSS components, this capability is likely to be leveraged by many organizations. SSL has become the standard mechanism for protecting web traffic &#8211; across the spectrum of Ecommerce, banking, health care, and so on. Providing SSL support for Central means that your components are no longer susceptible to man-in-the-middle attacks that could compromise the component. SSL also eliminates the potential for a hacker to gain visibility into your organization by tracking the components that you download for your development initiatives.</p>

<p>As of Nexus Pro 2.2 (available now), SSL is now the default connectivity option for Nexus Pro users. Because we take security of the ecosystem seriously, we aren&#8217;t stopping there, we&#8217;re making SSL connectivity to Central available to you even if you aren&#8217;t using Nexus Pro.</p>

<p>In order to ensure the highest level of performance for those who count on SSL, we are securing the service with a token. You can get a token for your organization simply by providing a $10 donation that will be donated to open source causes. For the first 60 days all donations will go to the Apache Software Foundation. After that, the donations will go to other open source foundations such as Eclipse. Sonatype will provide a donation on behalf of Nexus Pro customers since we&#8217;ve included SSL access to all Pro customers automatically.</p>

<p>If you happen to be using Nexus OSS (any version), support for the SSL token is included already. I&#8217;ve already reached out to the Artifactory and Archiva teams and they are working on the changes necessary to enable SSL to Central &#8211; we&#8217;ll let you know when that support is enabled. If you&#8217;re not using a repository manager at all, <a href="http://www.sonatype.com/people/2010/08/benefits-of-a-repository-manager-part-i/">what are you waiting for</a>?</p>

<p>If you are an existing Nexus Pro customer, you can download the latest release <a href="https://support.sonatype.com/entries/20673111-how-do-i-download-nexus-professional">from the support page</a>.</p>

<p>If you would like to make a donation to the open source community and get SSL access, <a href="http://www.sonatype.com/Products/Secure-Access-to-Central">you may do so here</a>.</p>

<p><img src="https://mail.google.com/mail/u/0/images/cleardot.gif" alt="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/10/now-available-ssl-connectivity-to-central/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Up Next: Nexus Support for Yum Repositories</title>
		<link>http://blog.sonatype.com/people/2012/09/up-next-nexus-support-for-yum-repositories/</link>
		<comments>http://blog.sonatype.com/people/2012/09/up-next-nexus-support-for-yum-repositories/#comments</comments>
		<pubDate>Thu, 27 Sep 2012 17:13:43 +0000</pubDate>
		<dc:creator>Jason van Zyl</dc:creator>
				<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[rpm]]></category>
		<category><![CDATA[yum]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=12273</guid>
		<description><![CDATA[The an upcoming release of Nexus OSS will have full support for Yum repositories. Sebastian Herold, with gracious support from IS24, has developed and contributed his code and time to integrate his Nexus Yum Plugin into the Nexus 2.x line. We have heard from many Nexus users, who are heading down the path of continuous [...]]]></description>
				<content:encoded><![CDATA[<p>The an upcoming release of Nexus OSS will have full support for Yum repositories. <a href="https://github.com/is24-herold">Sebastian Herold</a>, with gracious support from <a href="http://www.immobilienscout24.de/de/finden/wohnen/index.jsp;jsessionid=8B43A3881DD093521EB12BC42793E0BF.worker1">IS24</a>, has developed and contributed his code and time to integrate his Nexus Yum Plugin into the Nexus 2.x line. We have heard from many Nexus users, who are heading down the path of continuous delivery, that Yum support in Nexus to deliver RPMs to production servers is a critical requirement. Several of our customers have been using Sebastian&#8217;s plugin for quite some time and have been impressed and so we&#8217;re really excited about the integration of Yum functionality into Nexus OSS!</p>

<p>Some of you might be interested in using our Yum support to facilitate application deployment to staging and production networks. A lot of companies that deploy Java and other technologies end up packaging applications as RPMs and deploying them through Yum on Redhat or Centos because it provides a really easy way to manage, deploy, and rollback software packages in production. It is much easier to tell Operations to deploy RPMs than it is to draw up a series of instructions for installing Jetty or Tomcat from a tarball. To support these use cases, we&#8217;re going to invest some of our time developing more documentation and training to support developers that need to adapt applications to deployments that depend on this Yum integration.</p>

<p style="text-align: center;"><img class="aligncenter  wp-image-12277" title="NexusYumPlugin" src="http://www.sonatype.com/people/wp-content/uploads/2012/09/NexusYumPlugin.png" alt="" width="466" height="389" /></p>

<p>While Nexus is primarily used to support application development, this Yum support can be used on its own as a way to cache and simplify Yum repository configuration and package data. We&#8217;ll also be building out more examples of how Nexus can be integrated with infrastructure management tools such as chef and puppet.</p>

<h2>Features of the Nexus Yum Support</h2>

<p>As we integrate this feature into Nexus proper, here is the current list of features. We expect this support to evolve over time, but here&#8217;s what the plugin provides now.</p>

<ul>
    <li><strong>Expose an existing Maven repository as an RPM repository</strong> &#8211; Use a Maven repository, hosted in Nexus, containing RPMs as if it is a Yum repository. This leverages the virtual repository mechanism in Nexus which allows you to use Maven tooling to deploy RPMs into a Maven repository but still allow Yum clients to interact with the repository using the protocol it understands.</li>
    <li><strong>Automated Refresh of Repository Data</strong> &#8211; Yum repositories are automatically updated if you upload/deploy/delete a new RPM into Nexus. In a traditional RPM repository you have to run createrepo to refresh repository metadata. With Nexus this is all taken care of automatically.</li>
    <li><strong>Full group support</strong> so that you can logically group a set of Yum repositories behind a single URL. If your infrastructure relies on a number of remote RPM repositories you can consolidate OS configuration to point to a single Yum repository that can aggregate multiple repositories into one.</li>
    <li><strong>Versioned views on repositories:</strong> http://your.nexus/nexus/service/local/yum/repos/releases/1.2.3/ gives you a Yum repository with all packages in version 1.2.3 in repository releases. This particular feature is a game-changer for companies that release software using RPM as a delivery mechanism.</li>
    <li><strong>Alias Definitions for Specific Versions</strong> eg. production=1.2 and testing=2.0 and access them via the alias: http://your.nexus/nexus/service/local/yum/repos/releases/testing/ and http://your.nexus/nexus/service/local/yum/repos/releases/production/ to get constant repository URLs for your servers. A new release is then applied to the server by setting the alias to a new version.</li>
    <li><strong>createrepo Nexus Tasks Types</strong> &#8211; Create Yum createrepo tasks manually via web interface. Multiple createrepo tasks on the same repository are merged.</li>
    <li><strong>Full Integration with Nexus Staging</strong> &#8211; Use Yum group repositories as target of staging repositories (Nexus Pro). Stage RPM artifacts to development environments configured to pull artifact from Nexus repository groups./li&gt;</li>
</ul>

<p>You can find the <a href="https://github.com/sonatype/nexus-yum-plugin">source for the Nexus Yum Plugin in our Github Repository</a>. We would love your feedback as we still have time to make changes and improvements before the Nexus Yum Plugin is integrated into Nexus OSS proper.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/09/up-next-nexus-support-for-yum-repositories/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nexus 2.1: Fueled by Gun-Toting Unicorns with Jet Packs</title>
		<link>http://blog.sonatype.com/people/2012/09/nexus-2-1-fueled-by-gun-toting-unicorns-with-jet-packs/</link>
		<comments>http://blog.sonatype.com/people/2012/09/nexus-2-1-fueled-by-gun-toting-unicorns-with-jet-packs/#comments</comments>
		<pubDate>Thu, 06 Sep 2012 12:50:29 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[Nexus]]></category>
		<category><![CDATA[nexus professional]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=12060</guid>
		<description><![CDATA[At Sonatype, the stakes are high, and so our standards must be as well. We toil over every detail of the product, tweaking, refining, until we get things just right.]]></description>
				<content:encoded><![CDATA[<p>At Sonatype, the stakes are high, and so our standards must be as well. We toil over every detail of the product, tweaking, refining, until we get things just right.</p>

<p><img src="http://www.sonatype.com/people/wp-content/uploads/2012/09/Nexus-Splash-Screen-Thread1.png" alt="Nexus Splash Screen Email Thread" title="Nexus-Splash-Screen-Thread" width="641" height="1612" class="aligncenter size-full wp-image-12081" /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/09/nexus-2-1-fueled-by-gun-toting-unicorns-with-jet-packs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
