<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sonatype Blog &#187; Sonatype Insight</title>
	<atom:link href="http://blog.sonatype.com/people/tag/sonatype-insight/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sonatype.com/people</link>
	<description>Sonatype is transforming software development with tools, information and services that enable organizations to build better software, faster, using open-source components.</description>
	<lastBuildDate>Thu, 16 May 2013 18:53:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>New Webinar: Gain Visibility &amp; Control At Build Time with Insight for CI</title>
		<link>http://blog.sonatype.com/people/2012/05/new-webinar-gain-visibility-control-at-build-time-with-insight-for-ci/</link>
		<comments>http://blog.sonatype.com/people/2012/05/new-webinar-gain-visibility-control-at-build-time-with-insight-for-ci/#comments</comments>
		<pubDate>Tue, 15 May 2012 11:33:03 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[Hudson]]></category>
		<category><![CDATA[Insight]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[continuous integration]]></category>
		<category><![CDATA[Insight for CI]]></category>
		<category><![CDATA[Sonatype Insight]]></category>
		<category><![CDATA[Sonatype webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=11318</guid>
		<description><![CDATA[Join Brian Fox Wednesday, May 23 at 11AM EDT (GMT-0400) for a 30 minute tour of our latest innovation, Insight for CI. Brian will show you how Insight for CI will help you: Gain visibility and control at build time in Hudson and Jenkins. Find and fix license, security and quality problems quickly. Set rules [...]]]></description>
				<content:encoded><![CDATA[<p><img src="http://www.sonatype.com/people/wp-content/uploads/2012/05/blog_header_CIWebinarLaunch2.png" alt="" title="blog_header_CIWebinarLaunch" width="700" height="200" class="alignleft size-full wp-image-11398" style="padding-bottom:20px;"/>
Join Brian Fox Wednesday, May 23 at 11AM EDT (GMT-0400) for a 30 minute tour of our latest innovation, <a title="Insight_for_CI" href="http://sonatype.com/Products/Sonatype-Insight/Insight-for-CI" target="_blank">Insight for CI</a>. Brian will show you how Insight for CI will help you:</p>

<ul>
    <li>Gain visibility and control at build time in Hudson and Jenkins.</li>
    <li>Find and fix license, security and quality problems quickly.</li>
    <li>Set rules to notify you of problems or to fail builds.</li>
</ul>

<p>If you register, you&#8217;ll also receive access to the recording after the event. So if something comes up and you can&#8217;t make it, you won&#8217;t miss out.</p>

<p><strong><a title="Webinar Registration" href="http://sonatype.com/Request/Webinar-Registration/Introducing-Insight-for-CI-Visibility-Control-At-Build-Time?webinar=CILaunch_Blog&amp;utm_source=Blog&amp;utm_medium=Post&amp;utm_campaign=CILaunchWebinar" target="_blank">Reserve Your Seat Here</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2012/05/new-webinar-gain-visibility-control-at-build-time-with-insight-for-ci/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Will You Know When a Security Flaw is Found in a Production App?</title>
		<link>http://blog.sonatype.com/people/2011/10/will-you-know-when-a-security-flaw-is-found-in-a-production-app/</link>
		<comments>http://blog.sonatype.com/people/2011/10/will-you-know-when-a-security-flaw-is-found-in-a-production-app/#comments</comments>
		<pubDate>Mon, 10 Oct 2011 05:00:20 +0000</pubDate>
		<dc:creator>Tim O'Brien</dc:creator>
				<category><![CDATA[Insight]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Application Insight]]></category>
		<category><![CDATA[Sonatype Insight]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=9059</guid>
		<description><![CDATA[After developing enterprise applications for a number of years, I’ve noticed one common thread.   An application’s open source dependencies tend to stabilize over time.  An application with stable  dependencies requires less ongoing support, but it also introduces an often unacknowledged risk.  This article describes how Sonatype Insight can be used to constantly monitor deployed [...]]]></description>
				<content:encoded><![CDATA[<p>After developing enterprise applications for a number of years, I’ve noticed one common thread.   An application’s open source dependencies tend to stabilize over time.  An application with stable  dependencies requires less ongoing support, but it also introduces an often unacknowledged risk.  This article describes how Sonatype Insight can be used to constantly monitor deployed applications for new security risks.
<span id="more-9059"></span></p>

<p>As an application matures, it essentially becomes frozen in time.  As stability and production support become primary requirements, it is no longer a realistic option to upgrade to a new version of a critical framework.  Upgrading to a newer version of the Spring Framework or Hibernate become impractical when weighed against the need to reduce risk and reduce ongoing support costs for an application that has been deployed to production.</p>

<p>A large-scale project often selects a series of open source dependencies at the initial stages of application development.  Imagine you are working on an important customer service interface for a large company. This system is developed over the course of a number of years, and the first few months are characterized by large architectural changes. At the start of the project, the team experiments with newer versions of open source components and essentially “proves” an architecture.   As the project’s focus shifts toward business requirements and away from technology, management is less likely to give the go ahead for a critical technology upgrade.</p>

<p>In other words, that five year old web application that powers a core part of your business is probably using a five year old version of Hibernate or Spring.  Why?  For stability’s sake.  Why perform an upgrade if the system is still running?</p>

<p>What’s missing in these scenarios is an appreciation of the risks of standing still.  If you develop software using open source components, you are dealing with a steady stream of new releases and a constantly evolving set of relevant projects.  If you depend on an active project like ActiveMQ, Spring, or Hibernate, your development teams are dealing with a steady stream of releases, bug fixes, and bug reports. Good developers pay attention to these events and upgrade components with security risks as they are identified.</p>

<p>The problem arises when an application transitions from active development to production deployment.  When this happens, developers start to play a less important role in the day-to-day operation of the project. While you might have very quickly identified a critical security risk in an encryption library during the peak of the development lifecycle, a mature application doesn’t have as much attention from developers and there’s no good way to merge the steady stream of open source “events” with applications in production.</p>

<p>To address this issue, Sonatype created Application Insight.  Application Insight takes a production application and generates a bill of materials. This bill of materials is cross-checked against a stream of open source events and activity.  You will be notified immediately If a security vulnerability is identified in a component your application depends upon.</p>

<p>In other words, Sonatype’s Application Insight keeps a vigilant watch over applications that might not be getting as much developer attention.   It can identify previously unknown risks so that you can address the issue before it can be exploited.</p>

<p>Learn more about Sonatype Insight at <a title="Sonatype Insight" href="http://www.sonatype.com/Products/Sonatype-Insight">www.sonatype.com/Insight</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2011/10/will-you-know-when-a-security-flaw-is-found-in-a-production-app/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Webinar: Open Source Goodness minus Potential Risks = Insight</title>
		<link>http://blog.sonatype.com/people/2011/09/new-webinar-open-source-goodness-minus-potential-risks-insight/</link>
		<comments>http://blog.sonatype.com/people/2011/09/new-webinar-open-source-goodness-minus-potential-risks-insight/#comments</comments>
		<pubDate>Tue, 27 Sep 2011 01:27:30 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[Insight]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Sonatype Insight]]></category>
		<category><![CDATA[Sonatype webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=8986</guid>
		<description><![CDATA[Sonatype Insight™ helps development organizations gain better visibility and control over their use of open source components. With Insight, you&#8217;ll use open source freely while avoiding quality, security, or licensing issues. Insight was designed with developers in mind &#8212; it&#8217;s about productivity and quality, not bureaucracy and rework. Attend our webinar on Thursday, October 6th [...]]]></description>
				<content:encoded><![CDATA[<p><em>Sonatype Insight</em>™ helps development organizations gain  better visibility and control over their use of open source components.   With Insight, you&#8217;ll use open source freely while avoiding quality,  security, or licensing issues.  Insight was designed with developers in  mind &#8212; it&#8217;s about productivity and quality, not bureaucracy and rework.</p>

<p><strong>Attend our webinar on Thursday, October 6th at 10:30AM EDT (GMT-0400) to see how Insight:</strong></p>

<ul>
    <li>Helps you manage component quality, security, and licensing</li>
    <li>Integrates with your tools and processes</li>
    <li>Monitors your applications so you&#8217;ll know when a new defect is discovered</li>
</ul>

<p>Take 30 minutes and learn how you can build better software faster while avoiding unnecessary risks.</p>

<h4><a href="https://sonatype.webex.com/sonatype/onstage/g.php?t=a&amp;d=570572899"><strong>Register Now</strong></a></h4>

<p><em>All registrants will receive access to the recording after the event so  if something comes up and you can&#8217;t make it, you won&#8217;t be missing out.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2011/09/new-webinar-open-source-goodness-minus-potential-risks-insight/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Next Step in Transforming Software Development</title>
		<link>http://blog.sonatype.com/people/2011/09/the-next-step-in-transforming-software-development/</link>
		<comments>http://blog.sonatype.com/people/2011/09/the-next-step-in-transforming-software-development/#comments</comments>
		<pubDate>Mon, 19 Sep 2011 12:00:34 +0000</pubDate>
		<dc:creator>Wayne Jackson</dc:creator>
				<category><![CDATA[Insight]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Sonatype Insight]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=8968</guid>
		<description><![CDATA[Today we announced Sonatype Insight™, a new product line designed to help application development organizations gain better visibility and control over their use of open source components. This is an exciting step in the evolution of Sonatype. From our early beginnings with the Apache Maven project, to our leadership on such key projects as Nexus, [...]]]></description>
				<content:encoded><![CDATA[<p>Today we announced Sonatype Insight™, a new product line designed to help application development organizations gain better visibility and control over their use of open source components.</p>

<p>This is an exciting step in the evolution of Sonatype.</p>

<p>From our early beginnings with the Apache Maven project, to our leadership on such key projects as Nexus, m2eclipse, Hudson, p2 and Tycho, and through our stewardship of the Central Repository, we’ve always been committed to transforming software development through the use of open source.</p>

<p>What’s next?  How do we ensure the continued successful adoption and growth of open source in software development?  How do we help balance the beneficial economics, efficiency, and quality of open source with legitimate management concerns about quality, security, and licensing?</p>

<p>This challenge led us to build Insight. Insight lets developers leverage open source freely while reducing unnecessary risks.  It provides visibility and control without bureaucracy.  It enables governance without burden. In short, it’s a product suite that we, as developers, would be pleased to have in our environment.</p>

<p>Feedback from our pre-release customers has been very positive.  They see what we see – organizations need actionable information without disrupting their development processes.  They want to use more open source, but must avoid quality, security, and licensing risks.  They need productivity, not bureaucracy, manual research, and rework.</p>

<p>We’re excited about Insight and about our continued commitment to open source.  I’d encourage you to learn more at <a title="Sonatype Insight" href="http://www.sonatype.com/insight">www.sonatype.com/insight</a> or to contact me at <a href="mailto:wayne@sonatype.com">wayne@sonatype.com</a> if you have questions.</p>

<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2011/09/the-next-step-in-transforming-software-development/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
