Brian Fox

Brian Fox is a software developer, innovator and entrepreneur. He is an active contributor within the open source development community, most prominently as a member of the Apache Software Foundation and former Chair of the Apache Maven project. As the CTO and co-founder of Sonatype, he is focused on building a platform for developers and DevOps professionals to build high-quality, secure applications with open source components.

Anonymous Access In Nexus Repository is Not A Zero-Day Vulnerability

By Brian Fox on July 02, 2019 Nexus Repository

1 minute read time

A researcher contacted us about an issue in Nexus Repository, stemming from user access settings.
Read More...

Open Source Software Is Under Attack; New Event-Stream Hack Is Latest Proof

By Brian Fox on November 27, 2018 vulnerabilities

3 minute read time

Open source software is under attack, and the malicious attack on the popular npm event-stream 3 package, is just the latest proof.
Read More...

Deja Vu All Over Again - Another New Apache Struts Vulnerability (CVE-2018-11776)

By Brian Fox on August 23, 2018 Nexus Lifecycle

2 minute read time

Another remote code execution vulnerability in Apache’s Struts2 Framework was disclosed on August 22, 2018.
Read More...

Microsoft and Github: Open source’s future is brighter than ever

By Brian Fox on June 13, 2018 github

1 minute read time

With Microsoft’s resources behind a great company like GitHub, the future of secure, quality open source looks brighter than ever.
Read More...

Making sure our users don't zip-slip and fall

By Brian Fox on June 05, 2018 The Central Repository

1 minute read time

Sonatype has provided The Central Repository for over a decade and we take security of the users very seriously.
Read More...

Enhancing SSL security and HTTP/2 support for Maven Central

By Brian Fox on May 21, 2018 Central

1 minute read time

TLS and HTTP/2 changes coming to central
Read More...

Secure By Design: Preparing for GDPR Should Begin With Software

By Brian Fox on May 10, 2018 data protection

4 minute read time

To ensure GDPR compliance, appropriate safeguards must be put in place across the entire software lifecycle.
Read More...

Fooled twice by the same open source problem? Shame on you. The data behind CVE-2017-8046.

By Brian Fox on March 07, 2018 known vulnerability

2 minute read time

Organizations keep software applications safe, not by chance, but by preparation.
Read More...

Sonatype's 10 Year Journey, with Co-founder Brian Fox

By Brian Fox on February 16, 2018 Sonatype Nexus

3 minute read time

The fact that we are closing in on 200,000 open source instances of the Nexus Repository Manager is great to see. That transcends Maven usage.
Read More...