The Science of Compliance: Early Code to Secure Your Node

By Carlos Schults on April 27, 2020 Compliance

4 minute read time

Compliance testing can—and should—be done at all stages of your CI process. Watch your test tool – there can be false positives as well as false negatives.
Read More...

Nexus Firewall: Quality at Velocity

By Mike Hansen on November 17, 2015 nexus pro

5 minute read time

Nexus Firewall: Quality at Velocity
Read More...

The Cost to DevOps: 27 Mufflers

By Derek Weeks on July 16, 2015 Known Vulnerabilities

4 minute read time

Imagine that you are designing the 2016 Range Rover line of sport utility vehicles. Like all gas powered vehicles, each one needs an exhaust muffler.
Read More...

Better and Fewer Suppliers (2015 Software Supply Chain Report)

By Derek Weeks on June 17, 2015 governance

4 minute read time

Today I want to focus on the huge ecosystem of open source projects (“suppliers”) that feed a steady stream of innovative components into our software.
Read More...

DevOps Leadership Series: Gov Does DevOps (Part 2)

By Derek Weeks on June 02, 2015 Software Supply Chain

1 minute read time

During my second day at DevOpsDays DC, I had the opportunity to catch up with a couple more industry thought leaders.
Read More...

DevOps Leadership Series: Gov Does DevOps

By Derek Weeks on May 27, 2015 rugged

2 minute read time

This past week, I had the opportunity to catch up with some more industry thought leaders at the DevOpsDays DC event in our nation’s capital.
Read More...

3 Reasons Manual Policies Just Don’t Work

2 minute read time

Over the past four years, Sonatype has surveyed open source development organizations and year after year, we find that developers have the best intentions.
Read More...

PCI 3.0 - Secure Payment Requires Secure Components

By Derek Weeks on November 14, 2013 PCI

2 minute read time

PCI 3.0 - Secure Payment Requires Secure Components
Read More...