Brian Fox

Brian Fox is a software developer, innovator and entrepreneur. He is an active contributor within the open source development community, most prominently as a member of the Apache Software Foundation and former Chair of the Apache Maven project. As the CTO and co-founder of Sonatype, he is focused on building a platform for developers and DevOps professionals to build high-quality, secure applications with open source components.

Why Sonatype is acquiring MuseDev

By Brian Fox on March 16, 2021 Container Security

5 minute read time

Sonatype acquired MuseDev, a developer-first source code analysis platform and unveiled the world’s first full-spectrum platform for strengthening.
Read More...

Why namespacing matters in public open source repositories

By Brian Fox on February 10, 2021 The Central Repository

8 minute read time

Sonatype's CTO explains why the Central Repository has always required namespacing and why all public open source repositories should too.
Read More...

Dear Bintray and JCenter users - Here's what you need to know about the Central Repository

By Brian Fox on February 04, 2021 The Central Repository

3 minute read time

If you're freaking out about moving Java components into The Central Repository, following JFrog sunsetting Bintray, don’t worry. We’re here for you.
Read More...

Making developer's lives easier as we enter the new frontier of dependency management

By Brian Fox on October 07, 2020 featured

4 minute read time

Sonatype's Advanced Development Pack will fundamentally change how teams manage code dependencies.
Read More...

Octopus Scanner compromises 26 OSS projects on GitHub

By Brian Fox on May 31, 2020 #OSSsecurity

4 minute read time

The Octopus Scanner malware compromised 26 open source projects hosted on GitHub in a new form of software supply chain attack targeting NetBeans projects.
Read More...

Microsoft Acquires npm: A Healthy Move for Critical Public Infrastructure

By Brian Fox on March 16, 2020 github

3 minute read time

Today, news broke that GitHub and its parent company Microsoft, acquired npm and its public repository of open source JavaScript packages.
Read More...

The Dot Zero Conundrum and the New Frontier of Securing Open Source

By Brian Fox on September 24, 2019 code quality

3 minute read time

Sonatype is combining a new type of behavioral analysis with machine learning and proprietary data, creating early warning capabilities to detect malicious.
Read More...

Removing Search Guard from the Central Repository

By Brian Fox on September 11, 2019 The Central Repository

2 minute read time

Due to an intellectual property dispute between two third parties, Sonatype is legally required to remove disputed artifacts related to Search Guard from the.
Read More...

Anatomy of the RubyGems ‘rest-client’ Hack, and Getting Creative About Open Source Security

By Brian Fox on August 23, 2019 open source security

3 minute read time

Last month, the RubyGems strong_password component was breached and injected with malicious code.
Read More...