Sonatype Selected by Equifax to Support OS Governance Press Release

SON_logo_blog_2

Eight More Struts Breaches

Earlier today, Robert Hackett at Fortune published an eye opening report on the number of organizations who continue to download known vulnerable open

Read More...

Struts One-Two Punch Knocks Out India

By Derek Weeks on May 02, 2018 struts breach

The social security system of India, AADHAAR, was just breached due to a Struts related vulnerability exploited on their website.   If you are not familiar

Read More...

Open Source Governance Hits the C-Suite

By Derek Weeks on April 11, 2018 open source management

Earlier today, the Wall Street Journal’s Adam Janofsky wrote an article entitled,How Companies Can Manage Risks Tied to Open-Source Software*. Coverage of

Read More...

Nexus Repository 3.9 Released with a new Upload UI and Firewall Support

By Daniel Sauble on March 01, 2018 Nexus Repository OSS

We are pleased to announce the release of Nexus Repository 3.9. This release adds two major features:

Read More...

How a Software Bill of Materials Uncovers Known Vulnerabilities

In two minutes, we can show you a full software bill of materials for your application. We can also identify any known vulnerabilities in the open source

Read More...

Evaluating OSS logistics solutions? Consider these 9 tips.

By Derek Weeks on February 24, 2015 Sonatype vs. Black Duck

With well over 17 billion open source components downloaded from public repositories in 2014, it is clear that more software development organizations are

Read More...

Talking Turkey in Texas: Open Source Governance Lags

Deep in the heart of Texas, I was leading a panel discussion at the Lone Star Application Security Conference (LASCON) a few weeks ago. The panel was “

Read More...