Sonatype Delivers Premium Open Source Controls to GitHub | Press Release

blog-logo Sonatype Blog

Workflow Automation: Publishing Artifacts to Nexus Repository using Jenkins Pipelines

By Dmitriy Akulov on June 12, 2020 AppSec
Use Nexus Repo to create an automated workflow to build, store, organize, and monitor the compiled Maven artifacts through a CI server.
Read More...

NIST: Adopt a Secure Software Development Framework (SSDF) to Mitigate Risk of Software Vulnerabilities

NIST recommends a SSDF framework to assess open source component cybersecurity risks, including an SBOM and automated security controls in the SDLC.
Read More...

Can Kubernetes Keep a Secret?

By Daniel Longest on June 10, 2020 AppSec
Kubernetes Secrets store usernames and passwords as base-64 encoded strings. They are obscured from casual browsing, but this is the same as plaintext.
Read More...

New in Nexus Repository 3.24: Storage Optimization at Scale and NuGet V3 Hosted

By Brent Kostak on June 09, 2020 Product Release
Nexus Repository 3.24 offers enterprise admin capabilities and frictionless ecosystem support with new storage at scale and NuGet V3 hosting capabilities.
Read More...

How to Publish Docker Images on a Private Nexus Repository Using Jib Maven Plugin

By Awkash Agrawal on June 08, 2020 AppSec
Learn how to publish Docker images to a private Nexus repository with the help of the Maven Jib plugin.
Read More...

Smart Teams Use Atlassian and Sonatype to Plan Development Work

By Kevin Miller on June 05, 2020 JIRA
Shift open source governance into daily ticketing workflows. Teams can quickly assess risk and plan code fixes using Nexus Lifecycle and Jira Software.
Read More...

Did You Try Turning It Off and On?

By Mark Miller on June 05, 2020 devsecops
At one of the world's largest tech companies, the inability of approximately 13,000 employees to send and receive email was the catalyst for sheer panic.
Read More...

Using a Software Bill of Materials (SBOM) is Going Mainstream

Crazy: OWASP A9 is about to turn seven and the DevSecOps Community Survey shows less than half of organizations can produce a Software Bill of Materials.
Read More...

DevOps Assurance with OWASP SAMM

By Guillermo Salazar on June 02, 2020 OWASP
SAMM v2 follows three levels of maturity. Maturity levels 1 through 3 are similar to what, in other models, are known as crawling, walking, and running.
Read More...