blog/
1724 pages · Updated July 25, 2026
Pages
- News and Notes from the Makers of Nexus | Sonatype Blog | This Week in Malware
- News and Notes from the Makers of Nexus | Sonatype Blog | Guest Post
- News and Notes from the Makers of Nexus | Sonatype Blog | Theresa Mammarella
- News and Notes from the Makers of Nexus | Sonatype Blog | Katie McCaskey
- News and Notes from the Makers of Nexus | Sonatype Blog | Brent Kostak
- News and Notes from the Makers of Nexus | Sonatype Blog | Heather Loney
- News and Notes from the Makers of Nexus | Sonatype Blog | Matt Howard
- News and Notes from the Makers of Nexus | Sonatype Blog | Michelle Dufty
- News and Notes from the Makers of Nexus | Sonatype Blog | Sonatype
- Wicked Good Development Episode 2: Starting Security Left
- Malicious 'aptX' Python Package Drops Meterpreter Shell
- Comparing and Converting SBOM Formats: CycloneDX vs. SPDX
- Storage Management Best Practices: Expand Storage With Ease
- StringJS Typosquat Deploys Discord Infostealer Obfuscated
- The Science of Compliance: The Importance of DevSecOps | Sonatype
- Polyfill.io Supply Chain Attack Explained | Sonatype
- Generate PGP Signatures for Maven Projects: A Complete Guide
- DevOps Tools, Not Rules | Sonatype
- Embedding Ownership: A DevOps Best Practice
- Defining Roles for Staging: Sonatype Tips and Tricks
- How to Effectively Backup Sonatype Nexus Repository
- Automate and Maintain SBOMs for Better Software Security
- Open is Not Costless: Reclaiming Sustainable Infrastructure
- DevOps-as-a-Service: Overcoming Challenges in Large Organizations
- SBOM Best Practices: Tips from Global Technology Leaders
- Meet an Open Source Developer: Allie Sierra
- Sonatype Learn: Source Control Management (SCM) Onboarding
- Explore This Interactive DevSecOps Reference Architecture
- Understanding the Risks and Exploits of Java Serialization
- CocoaPods and Conda Support in Sonatype Nexus Repository
- Extracting Android Project Dependencies Using Gradle Tasks
- Being the 'B' in LGBTQIA+
- Zero Day, Now What?
- Malicious PyPI Packages Compromise Telegram Cache Files
- Sonatype Nexus Repository Now Has Improved Search Interface
- npm Registry Flooded with 748 Movie-Storing Packages
- The importance of Maven training | Sonatype Blog
- DevSecOps: In Time for Security
- NVD Overload: A Critical Vulnerability Management Challenge
- Enhance SSL Security and Support for HTTP/2 in Maven Central
- Lessons Learned From Equifax Testifying to Congress
- Celebrating the 2025 Sonatype Elevate Awards Finalists
- Docker Image Security for DevSecOps | Sonatype Blog
- CVE-2020-17479: Validation Bypass (CVE-2019-19507) in `jpv`
- OSS Malware: VMware Dependency Confusion and Secrets Management Issues
- Understand the Cyber Resilience Act: Key Compliance Insights
- Sonatype Donates Maven 3.x Eclipse Integration to Hudson
- Sonatype DepShield Now Protects npm Projects
- Optimizing Disk Space for Nexus Repository Manager
- Mastering Dependency Mapping: Essential Guide for Developers
- Unlocking Cyber Readiness: The Role of SBOMs in Security
- News and Notes from the Makers of Nexus | Sonatype Blog | Kevin Miller
- Creating a Maven Plugin That Executes Only Once Per Build
- Announcing Sonatype Nexus Repository Beta | Sonatype Blog
- News and Notes from the Makers of Nexus | Sonatype Blog | Stephen Magill
- News and Notes from the Makers of Nexus | Sonatype Blog | Ryan Berg
- News and Notes from the Makers of Nexus | Sonatype Blog | Curtis Yanko
- News and Notes from the Makers of Nexus | Sonatype Blog | Marvin Froeder
- News and Notes from the Makers of Nexus | Sonatype Blog | VAO
- News and Notes from the Makers of Nexus | Sonatype Blog | Mitchell Johnson
- News and Notes from the Makers of Nexus | Sonatype Blog | John Casey
- Secure Your SDLC with DoD Zero Trust Architecture | Sonatype
- The Importance of Namespacing in Open Source Repositories
- Malicious Python Packages Mimic 'Requests' Library
- News and Notes from the Makers of Nexus | Sonatype Blog | Jeff Wayman
- CVE-2019-13354: strong_password embedded malicious code
- Second Coming of Shai-Hulud: Attackers Innovate on npm | Sonatype
- 200+ Cryptomining Packages Found in npm and PyPI Registries
- Keeping Your Sonatype Nexus Repository Clean Just Got Easier
- The Essential Duo: SBOM Management and SCA Security
- CVE-2019-3773: Critical XXE Vulnerability in Spring Web
- Open Source Observations From RSA
- Best Practices to Secure Open Source Projects Using SBOMs
- The Importance of Sustainable Open Source Infrastructure
- Repo Hijacking: Is the Popular npm Package qr.js Still Safe?
- News and Notes from the Makers of Nexus | Sonatype Blog | Bruce Mayhew
- Maximize Software Security: How SBOMs Enhance SCA Strategies
- Apache Maven 2.2.1 Released: New Features Explained
- Addressing Maven Problems on the JBoss Wiki: Part 3 Insights
- Sonatype Board Member Ann Winblad Talks DevOps & Open Source
- Secure Your SDLC with Open Source Risk Management | Sonatype
- Maven Archetypes and Nexus: There is no faster way
- Speed Up Maven Builds: An Approach to Dependency Management
- Exploring Nexus Repository: The Role of a Repository Manager
- Three Days of DevSecOps: Lessons From Equifax | Sonatype
- Nexus Repository: A Private Docker Registry on Kubernetes
- Java Serialization - The Gift That Keeps on Taking (Part 3)
- This Week in Malware - Over 100 Packages Discovered | Sonatype
- Dept. of Homeland Security: Top 10 Exploited Vulnerabilities
- DevOps Table Stakes: The Minimum Amount Required to Play the Game
- The Importance of SCA in Open Source Security | Sonatype
- Enhance Development Security: Lessons from Log4j and Beyond
- This Week in Malware - Ongoing Dependency Confusion | Sonatype
- Decade of Open Source: Insights & Future Security Strategies
- Enhancing Software Security with CISA's Latest SBOM Guidance
- Secure Your SDLC with Sonatype and GitHub Integration
- What Is Software Dependency Management?
- Time for Full Open Source Disclosure
- Downloading Artifacts from Nexus with Bash: A Simple Guide
- Implementing DevSecOps With 1,162 Apps
- CLM Customer Impressions
- The Open Source Vulnerability That Keeps on Giving
- ChatGPT Leak: Unfixed Redis Race Condition Vulnerability
- Evaluate Open Source Components Before Use | Development Tip
- A Time for Federal Software Supply Chain Management
- New Dependency Management Frontier Improves Developer Speed
- System Hardening with Ansible: Automate Security for DevOps
- Sonatype Users Reveal the Benefits of Automated DevSecOps
- Meet an Open Source Contributor: Amy Keibler
- Going to DevOps Enterprise Summit London With an Open Mindset
- Software Supply Chain Attacks: Lessons Beyond Supermicro
- JBoss Switches to Sonatype Nexus Repository | Sonatype Blog
- Nexus Enhances Component Management with New Security Features
- A Non-Programmer's Introduction to the Software Supply Chain
- Understand NuGet for Java Developers: Bridging .NET and Java
- UK Government to Step Up Supply Chain Security Following EO 14028
- How The Unicorn Project Aligns With The Phoenix Project
- Pin the Snapshot dependency versions in your POM | Sonatype Blog
- The Landscape of Open Source Supply Chain Attacks: Part 3
- Securing Financial Institutions Against DORA ICT Risk
- Meet Richard Panman: Values Champion
- Sonatype Firewall Now Supports JFrog Artifactory
- Scan Your Application for Security and Licensing Issues
- Writing plugins for Nexus (Part 2) | Sonatype Blog
- Why Including Repositories in POM Files Is Problematic
- Comparing Sonatype Nexus Repository to Everyone Else
- I want to write really insecure code today | Sonatype Blog
- Build Better Code Using Sonatype's Integrations With Atlassian
- Maven: The Integration Bridge for Modern Enterprise Development
- Gartner goes development-centric | Sonatype Blog
- What Does DevOps Maturity Tell Us About Security Maturity?
- Improving DevSecOps at the GSA | Sonatype Blog
- Nexus Live, October 2014 - Gene Kim, Josh Corman, TheNEXUS
- Explore New Features in Sonatype Nexus Repository 1.8.0.1
- Minimize Development Risk with Better Repository Management
- News and Notes from the Makers of Nexus | Sonatype Blog | security vulnerabilities
- This Week: Killing Windows Defender With an npm Package
- Procure Secure Components Faster and Manage Risk Better
- Software Supply Chain Best Practices: Future-Proofing With SCA
- Wicked Good Development: The Secret Life of Maven Central
- Why Your Enterprise Needs a Binary Repository Manager
- And Then, Our CEO Won Entrepreneur of the Year
- Sonatype Intelligence: CVE-2017-5662 - Cross-Site Scripting
- Strengthening Software Supply Chains: Why Grafeas Is a Great Idea
- npm Packages Found Exfiltrating Kubernetes Config & SSH Keys
- What Is Grounding? Why AI Coding Assistants Need Better Intelligence
- Code and congress: A time for cyber supply chain management
- Auditing SBOMs: Enhancing Software Security and Compliance
- News and Notes from the Makers of Nexus | Sonatype Blog | Audra Davis-Hurst
- Strategies to Secure Multi-Environment Deployments
- News and Notes from the Makers of Nexus | Sonatype Blog | Malware Monthly
- The Landscape of Open Source Supply Chain Attacks: Part 2
- Walmart Adopts Sonatype Nexus, OneOps, Jenkins, Kubernetes
- Apache Struts2 Critical File Vulnerability: CVE-2024-53677
- Malware Insights: Malicious Rust Crate and Colors Typosquats
- News and Notes from the Makers of Nexus | Sonatype Blog | Elissa Walters
- Navigating Open Source Growth | Sonatype Blog
- Access npm Packages After Securing Sonatype Nexus Repository
- It Pays to Discover Sonatype
- Optimal Sonatype Nexus Repository Configuration | Sonatype Blog
- Enabling Access Logging in Sonatype Nexus Repository 1.3.6
- 400+ npm Packages Target Azure, Uber, Airbnb Developers
- AI Technologies | The Future of Innovation & Efficiency
- Shift Left: Operationalizing Security Controls via DevSecOps
- House Oversight: Equifax Open Source Breach Was Preventable
- Two Years of Flexmojos: Exploring Versions 3.6 and 4.0 Pre-Alpha
- Flexibility in Maven 3.x: Exploring Polyglot and ModelReaders
- How to Manage OSS Forges Using Sonatype Nexus Repository
- News and Notes from the Makers of Nexus | Sonatype Blog | Paul Horton
- Browsing Javadocs and Archives Made Easy with Nexus Repository 1.5.0
- Cybersecurity Awareness Month: Strengthen Digital Defenses
- FDA: DevSecOps and Nobody Dies
- New PyPI Cryptomining Malware Discovered by Sonatype
- Seamless Sonatype Nexus Repository Upgrade: A User Success Story
- Unveiling npm Manifest Confusion: Risks and Solutions
- Nexus Repository Achieves Certification in Red Hat OpenShift
- Migrating from Artifactory to Nexus: Ning's Success Story
- Are You Impacted by Struts2: Free Application Health Check
- Federal Technology Trends 2025: A Retrospective | Sonatype
- What Are SBOM Standards and Formats? | Sonatype
- Sonatype Nexus Repository Deployment Guidelines
- Enhance Apache Log4j Security with SBOM and VDR Integration
- How Manufacturing Practices Improve Open Source Consumption
- How to Become an Open Source Contributor
- AppSec EU 2017 Belfast – What to Expect
- New Ecosystems in Sonatype Lifecycle and Firewall
- Wicked Good Development: Issues with Open Source Licensing
- Migrating from JCenter/Bintray to Maven Central | Sonatype
- Sonatype Discovers Two Malicious npm Packages
- White House Executive Order on U.S. Software Supply Chains
- Explore npm search changes | Sonatype Blog
- How to Navigate DevOps Principles: Analyzing Shift Left
- Kaseya Ransomware: A Software Supply Chain Attack or Not?
- Part 1, the Internet of Everything: Code, Cars, and More
- Sonatype Relocates Headquarters to Maryland
- Sonatype Automated Deployments With Atlassian Bitbucket Pipelines
- Securing Development Infrastructure in Software Security
- Releases are Forever? | Sonatype Blog
- Enhance Software Security with SLSA and Sonatype | Blog
- Sonatype Nexus Repository 3.5: Introducing Yum Proxy Support
- The Most Underutilized Policy Type in Sonatype Lifecycle | Sonatype
- The Importance of Having an Open Source Policy
- Sonatype Nexus Repository 1.1 Released | Sonatype Blog
- Optimizing Maven Builds for Continuous Integration Success
- Sonatype Nexus Repository: Release 1.9-M1 Now Available
- CVE-2019-0232: Apache Tomcat Remote Code Execution
- A Path Towards Secure and Maintainable Open Source Software
- Wicked Good Development Episode 16: Ted Neward's Philosophy 101
- Making Sure Our Users Don't Zip-Slip and Fall
- Top questions answered when selecting OSS components
- How to Establish an Open Source Program Office
- Stay Ahead of Security Flaws in Your Production Apps
- Equifax Was 100% Preventable, But 18,000 Others At Risk
- Rust Language Adoption: Balancing Performance and Memory
- 9 Reasons to Implement a Repository Manager with Sonatype
- Safeguarding OSS with Lessons from the Bootstrap-sass Hack
- Exploring The LLM Dependency Trap | Sonatype
- Book Update: Repository Management With Nexus
- Maven 2.0.9 Release: Information on Maven Plugin Versions
- Securing the Software Supply Chain: A Federal Imperative for 2026
- Is Cyber Liability Insurance a Moral Hazard in the US?
- Leveling Up: How to Improve Your ACSC Recommended Maturity Model
- Wicked Good Development: Devoxx Poland Developer Conference
- Streamline Open Source Security with Automated SCA Tools
- Is Sonatype Auditor Right for Your Applications? | Sonatype
- DevOps Leadership Series: Gov Does DevOps
- New policy grandfathering: Automating open source governance
- Sonatype Unveils Artificial Intelligence Component Detection
- Streamline Maven Projects: Dependency Grouping Techniques
- Effective Tools for Software Composition Analysis (SCA)
- The Shift Toward Unified Platforms in Application Security | Sonatype
- Validate Sigstore Signatures in Central Publisher Portal
- Researchers Say Development Velocity Is a Good Thing
- Preparing for EU CRA Compliance: Steps for Development Teams
- Assess Open Source Software Security: Explore Strategies
- Building Maven Central Search: Leveraging Solr and AJAX
- Securing Repository Credentials with Nexus User Tokens
- Enhancements to Maven Central | Sonatype Blog
- Sonatype Nexus Repository + Atlassian Crowd Plugin
- Sonatype, Continuous Delivery, and DevOps: Slideshow Gallery
- Struts2 vulnerabilities: Who is responsible? | Sonatype Blog
- News and Notes from the Makers of Nexus | Sonatype Blog | Chris Good
- Building Eclipse Plugins With Maven: Tycho | Sonatype Blog
- Mavenizing the AppEngine SDK | Sonatype Blog
- Understanding and Securing Your Software Supply Chain
- Fake Solana Packages Target Crypto Devs, Abuse Slack & ImgBB
- Secure Nexus Repository Setup & LDAP Integration | Sonatype
- Backing Up Sonatype Nexus Repository Configuration and Artifacts
- Experimenting With the Nexus Welcome Page
- Q1 2026 Open Source Malware Index: Adaptive Attacks Exploit Trust
- Optimizing Hudson Build Farms: Overcoming Windows Integration Issues
- Reference Platform: Kompose, OpenShift, and Helm
- Trust and Courage Are Essential for Team Culture | Sonatype
- News and Notes from the Makers of Nexus | Sonatype Blog | DJ Schleen
- Transform Software Compliance With AI SBOM Management | Sonatype
- Java at 30: Evolution, Enterprise Java & History | Sonatype
- Top Malicious npm Packages Targeting Open Source Projects
- Continuous Integration with Jenkins, Nexus, and SonarQube
- News and Notes from the Makers of Nexus | Sonatype Blog | Juan Aguirre
- Handling Conflicting OSS Licenses with Insight | Sonatype
- Scaling Secure Swift Development with Sonatype Nexus Repository
- News and Notes from the Makers of Nexus | Sonatype Blog | Terry Bernstein
- NIS2 Readiness: Key Steps for EU Cybersecurity Compliance
- News and Notes from the Makers of Nexus | Sonatype Blog | osstop10
- Misused Maven Terms Defined | Sonatype Blog
- Explore Cryptic 'reverse shell' Lurking in PyPI Packages
- What's in Maven 3.0 for Plugin Authors?
- Navigating New Federal SBOM Requirements for Cyber-Readiness
- Gartner: You Must Assess Overall Software Health and Welfare
- GDPR Compliance? Lessons Learned from Equifax
- This Week in Malware - Almost 100 Packages | Sonatype
- Sonatype Nexus Repository 3.0 FAQs Asked and Answered
- The AI Race Is Becoming a Remediation Race
- How DevSecOps is Transforming Application Security
- Foreword | Sonatype Blog
- DevSecOps at Emerasoft: Sonatype Lifecycle and F5-Advanced WAF
- On International Women's Day, I Honor My Grandma's Nudge
- Sonatype Platform Features: New Capabilities & Product Names
- The Golden Repo Is Not the Answer, the Golden Policy Is
- Exploring The Department of Defense DevSecOps Transformation
- How to Streamline Open Source with Sonatype Nexus Repository
- Process Oriented Design (POD) to Increase the Dependability
- Understanding and Preventing Dependency Confusion Attacks
- The Essential Elements of an SBOM for Software Security
- Apache Servers Under Attack: Urgent Need for Prompt Patching
- Exploring the Federal Government's Response to Log4j
- Deloitte Names Sonatype in the Technology Fast 500
- Red Hat Cloud Services npm Packages Hijacked
- Flaws vs. Bugs
- Trusting Third-Party Code That Can't Be Trusted
- HTTPS Support Launching Now
- Setting Up Integration Tests in Maven Using the Failsafe Plugin
- Netmask Flaw and PHP Git Server Hack Expose Millions
- We're used to the axe grinding | Sonatype blog
- In Other News | Sonatype Blog
- Sonatype Innovate: Real Peer Connections in Software Security
- How to Prevent Maven from Downloading Excessive Dependencies
- Scale Developer Security With Expanded Sonatype Platform Features
- Sonatype Hosts Global Gatherings of DevSecOps Leaders
- Developer Insights on Maven and Selenium in Weekly Roundup
- Nexus REST API: Documentation and Browser Tools Explained
- Easily Move Artifacts Between Sonatype Nexus Repositories
- Academy Software Foundation: Hollywood Embraces Open Source
- Creating an OSS Policy: Considerations and Best Practices
- Enhancing Docker Security with Sonatype Nexus Repository
- Open Source Software Efficiency & OSS Optimization | Sonatype
- Exploring Maven 3.0 Project Model and Mixins | Sonatype
- Sonatype: Fighting COVID-19 Together
- Streamlining Developer Onboarding with Maven Studio for Eclipse
- Maven Guide Split into Two Comprehensive Books | Sonatype
- News and Notes from the Makers of Nexus | Sonatype Blog | Elisa Velarde
- News and Notes from the Makers of Nexus | Sonatype Blog | Luke Mcbride
- News and Notes from the Makers of Nexus | Sonatype Blog | Jason van Zyl
- News and Notes from the Makers of Nexus | Sonatype Blog | Michael Prescott
- News and Notes from the Makers of Nexus | Sonatype Blog | Mark Miller
- index.html
- News and Notes from the Makers of Nexus | Sonatype Blog | Derek Weeks
- News and Notes from the Makers of Nexus | Sonatype Blog | Tim OBrien
- News and Notes from the Makers of Nexus | Sonatype Blog | Brian Fox
- News and Notes from the Makers of Nexus | Sonatype Blog | Ax Sharma
- News and Notes from the Makers of Nexus | Sonatype Blog | Sonatype Research Team
- News and Notes from the Makers of Nexus | Sonatype Blog | Emily Blades
- News and Notes from the Makers of Nexus | Sonatype Blog | Ilkka Turunen
- Malware Monthly: Insights into Malicious Packages & Attacks
- News and Notes from the Makers of Nexus | Sonatype Blog | Aaron Linskens
- OSS Security: A Guide to Open Source Software Risk | Sonatype
- How to Secure Jackson-Databind Deserialization Vulnerability
- DevOps Pioneers Navigate Organizational Transformation
- Best Practices to Harness AI in Software Supply Chains
- What Is Dependency Confusion in the Federal Sector?
- Why You Need a Software Bill of Materials More Than Ever
- The First Mile of Trusted AI Development | Sonatype
- Optimizing Software Dependency Management for Better Results
- Malware Monthly: Insights on Software Supply Chain Attacks
- Struts2 Exploited Again. Did Anyone Bother to Tell You?
- LLM Embedding Security: Vector Database Risks | Sonatype
- Using Webhooks to Integrate Lifecycle With Red Hat Quay
- Two New RubyGems Laced with Cryptocurrency-Stealing Malware
- The 3 Ways of DevOps: A Framework for Transformation
- Accelerate Software Delivery with the DoD's SWFT Initiative
- npm Package Could Have Brought Down Cloudflare's Entire CDN
- Simplifying Sonatype Platform Setup with Docker Compose
- Octopus Scanner Malware Compromises OSS Projects on GitHub
- Keep Software Dependencies Secure with Sonatype Lifecycle
- What Do Log4Shell and a Global Pandemic Have in Common?
- PyPI Package Targets Windows With NullRAT Info-Stealer
- Happy Developers Are the Key to Secure Financial Software
- DevOps At the US Patent and Trademark Office
- Identify Vulnerable Components Using Sonatype Lifecycle
- The Hidden National Security Threat Inside AI-Driven Software
- AI Is Forcing a New Open Source Security Model
- Explore NIST’s Secure Software Development Framework
- Addressing Organizational Overconsumption in Maven Central
- Sonatype Nexus: The Future of DevOps and Dependency Management
- Data Behind CVE-2017-8046: The Same OSS Problem Occurs Twice
- DevSecOps Elite and Their Reference Architecture
- Azure DevOps Integration Enhances Sonatype Lifecycle
- Open Source Development Survey: Making Results Matter
- Optimize Your Builds: The Importance of Proxying Maven Central
- GitHub Integration With Sonatype Lifecycle
- How Rube Goldberg Cartoons Relate to Inefficient Build Systems
- AI Component Analysis in Software Supply Chain Security
- Easily Scale Up with Docker Subdomain Routing | Sonatype
- Introducing the Nexus Remote Repository Browsing Plugin
- Containerize Your Excitement: Sonatype Nexus Repository 3 Release
- Riot Games Shares Its Chef Cookbook for Nexus
- Secure Dependencies: Sonatype Lifecycle's Automated Pull Requests
- Maven Tips: Creating an OSGi project with Maven | Sonatype
- Prioritize Open Source Vulnerabilities with Reachability
- Federal Software Security: Awareness to Assurance | Sonatype
- Secure Connectivity: Artifactory and Archiva Now Supported
- The Fact is Your DevOps Processes Have Gone Horribly Wrong
- Common cybersecurity acronyms explained
- Top Maven How-Tos for Developers from Sonatype
- How to Search the Maven Repository | Sonatype Blog
- Sonatype Learn: Explore Self-Service Educational Materials
- Malware Wrap-up: 135 Packages Target npm and PyPI Registries
- Struts2 Vulnerability Cracks Equifax | Sonatype
- Neglecting Application Security Is A Risk You Can't Afford
- Hidden Costs of Open Source Tooling: Why Free Isn't Free
- Microsoft and GitHub: Open Source's Future is Brighter Than Ever
- GitHub ID Hijacking: Exploring The Go-Bindata Incident
- This Week in Malware - Show Me Your Secrets | Sonatype
- Customizing Sonatype IQ Server with Docker Compose
- Enhancing CI/CD Pipelines with Sonatype and Bitbucket Code
- PGP vs. Sigstore: Code Signing Tools at Maven Central
- Enhance Software Quality with Sonatype Firewall
- DevSecOps Without Compromise
- Three Approaches to User Management in Nexus | Sonatype Blog
- Searching with Sonatype Nexus REST API: Groovy | Sonatype
- Best Practices Insights for Authentication & Authorization
- New Year, New CVE: Diving Into 'node-forge' (CVE-2022-0122)
- Wicked Good Development Episode 26: Tom Cools
- Part 3, the Internet of Everything: Code, Cars, and More
- New in m2e 0.12.1 - Maven 3.0.2, Async HTTP Client
- A Home for the Central Repository
- Sonatype Celebrates February 3, 2022 as World Open Source Day
- Government Asks: What's in Your Software?
- Linux and Mac Malware Disguised as Browserify npm Package
- Choosing the Right SBOM Standard: SPDX vs. CycloneDX
- Streamlining Compliance: How Compliance As Code Simplifies the Process
- CrowdStrike Incident: Lessons on Digital Resilience
- Master InnerSource: Explore Sonatype's InnerSource Insight
- Are you using a Leiningen repository manager | Sonatype blog
- CVE-2017-17461: Uncovering a Critical ReDoS Vulnerability
- Managing Open Source Risks with HeroDevs EOL Dashboard
- Introducing GoNexus: Enhancing Reliability for Go Developers
- A Guide to Deploying and Owning DevSecOps in Government
- Despite What Some Vendors Say, Please Don't Ignore Log4j
- Log4Shell Exploit: Understand the Impact of CVE-2021-44228
- When AI Writes Code, Who Governs the Dependencies?
- Google Guava shows strong growth in April | Sonatype Blog
- What Is Container Security, and How Can You Boost Yours?
- Revolutionizing Software Development: Frank Roe's Insights
- Listen to Brian Fox Discuss Maven 3 on BasementCoders.com
- Weaponizing Open Source Through Job Recruiting | Sonatype
- Open source governance starts with visibility | Sonatype Blog
- Maven by Example now available as an ePub | Sonatype Blog
- Maximize Security: Understand the Impact of Security Testing
- Exploring the Nexus OSS Switch to the Eclipse Public License
- Nexus Indexer 2.0: Save Bandwidth with Incremental Downloading
- New in Nexus Repository: More Formats and Stronger Operations
- Sonatype Achieves SOC 2 Certification | Sonatype
- Simplified Policy Management with Sonatype Nexus Repository
- Exploring How Kubernetes Enables DevOps | Sonatype
- Integrating Nexus Indexer API: Advanced Search Techniques
- New Dashboard Helps Build a Business Case for DevSecOps
- Deploying DevOps in Government: The Second Time Is the Charm
- How to Build a Software Supply Chain Security Playbook
- Top 8 Malicious Packages Recently Found on PyPI | Sonatype
- PSA: Your Build Is Leaking (and How to Stop It) | Sonatype
- Read the Sonatype Newsletter | Sonatype Blog
- Set Up Nexus Repository as a Windows Docker Container Registry
- 5 Things You Need to Know About Open Source Components
- Sonatype CEO on the Future of the Software Supply Chain
- Securing Your IT Supply Chain: Key Insights and Strategies
- Delivering on a promise: Free Nexus training | Sonatype blog
- Wicked Good Development: Devnexus Reflections & Convos
- Hygiene for Open Source Is Now a PCI Requirement | Sonatype
- Violations Detailed View Coming to Sonatype IQ Server | Sonatype
- How to Become an OSS Champion
- New Product Capabilities for Software Supply Chain Security
- Who Really Wrote healthcare.gov?
- The Evolution of Open Source Malware: From Volume to Trust Abuse
- Why Does Security Matter for DevOps?
- The 2014 Survey: Marked By an Industry Shockwave
- Protect Your Software Supply Chain with Firewall
- Sonatype Lifecycle and Firewall Now Available in the Cloud
- Anonymous Access in Sonatype Nexus Repository Is Not a Zero-Day
- Bryan Batty von der Bloomberg Industry Group, Teil 4
- Wicked Good Development: New National Cybersecurity Strategy
- Analyzing Python Malware: A Guide to Malware Analysis
- The Emerging Role of the ALM Architect in IT Governance
- Security by Design: The Benefits of Building Quality In
- The Overview Effect: Transforming Development Perspectives
- Software Supply Chain Readiness: Unmanned Aircraft Systems
- Guide to Choosing Between Nexus and Nexus Professional
- Maven Shell Introduction: How to Speed Up Your Builds | Sonatype
- Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies
- Code Quality Checks: Tools to Improve Your Software | Sonatype
- Leading a DevOps Team at a Fortune 100 Company
- Another SolarWinds? New Software Supply Chain Attack on 3CX
- All Things Maven: A Discussion With Brian Fox
- Sonatype Intelligence CVE-2019-15753: OpenStack (os-vif)
- New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages
- What the 2026 Software Supply Chain Report Reveals About Regulation
- How to Easily Identify Conda Vulnerabilities Using Sonatype Jake
- Apache Struts2 Vulnerability Downloaded 387K+ Times Last Week
- How to Integrate Aether in Maven 3 Plugins for Dependency Resolution
- Managing Nexus API Using Jenkins X
- Building Trusted AI Development With Antigravity and Sonatype Guide
- AI Risk Management Framework for Federal Security | Sonatype
- Sonatype Named DevOps Dozen Winner for Best DevSecOps Solution
- Now Available: m2eclipse 0.10.0 | Sonatype Blog
- Nexus Holds the Top Market Share, the Data Speaks for Itself
- Nexus Repository 3.20 Install, Admin Login, and Port Change
- Follow Sonatype on Twitter | Sonatype Blog
- Accelerate Productivity, Digital Value Streams, & DevSecOps
- DevOps for Small Organizations: Lessons From Ed
- Optimizing VMware for Efficient Hudson Build Farms | Sonatype
- Software success at Fannie Mae is paved with DevOps-native tools
- US Energy and Commerce Committee: 6 Strategies for Modern Risks
- PyPI Package 'ctx' and PHP Library 'phpass' Compromised
- From Good to Great with Software Composition Analysis (SCA)
- Understanding Havij: A Tool for SQL Injection Testing
- Protecting Containers to Secure Your Business | Sonatype
- Meet an Open Source Developer: A.J. Brown
- Wicked Good Development Episode 6: The Logic of Code Quality
- Explore Two More Reasons Why Sonatype's Future Is Bright
- The OWASP ZAP HUD | Sonatype Blog
- Why We Chose the GPL for Sonatype Nexus Repository | Blog
- Streamlining Apache Portals Releases with Nexus Staging Suite
- Benefits of a Repository Manager: Caching and Collaborating
- Codecov Breach: An Undetected Software Supply Chain Attack
- Did You Wake Up to a Java Deserialization Vulnerability Alert?
- Explore New Ecosystems Available Sonatype Lifecycle
- Over Five Dozen More Malicious Packages Discovered | Sonatype
- Developing an Ansible Role for Sonatype Nexus Repository v3.x
- Inevitable: Earthquakes and Exploits
- Navigating the Challenges of Shadow AI in Modern Business
- Modernizing Federal DevSecOps for CMMC and Beyond
- Log4j 2.17.1 Fixes Vulnerability: Should You Be Concerned?
- The Critical Importance of OSS License Compliance
- Twilio-npm Package is Brandjacking Malware in Disguise
- DevSecOps Leadership Forum: 500 Innovators Unite
- 2025 Sonatype Elevate Awards: Submissions Now Open
- Best Practices for Managing Software Supply Chain Security
- Integrating Nexus Indexer API: Packing and Updating Explained
- Setting Up a Private Docker Registry with Nexus Repository
- Explore Sonatype's Response to CISA's Secure by Design
- Unmasking Open Source Malware: Insights from ADDO Keynote
- Build Promotion with Nexus Professional | Sonatype Blog
- EclipseMagazine Interview on Maven Ecosystem with Sonatype
- Sonatype and Bamboo: Improving Your Builds
- How Sonatype's Container Scanning Protects You From Zero-Days
- A Decade of Change: Insights from the 2024 SSC Report
- Maven and Nexus Tips and Tricks Roundup | Sonatype Blog
- Roblox and Fortnite Spam Floods PyPI, NuGet, and npm
- npm Package Found Disabling Windows Defender to Drop Trojan
- New Learning Module for Maven Repository Configuration
- They Sent 300 Employees to a DevOps Conference
- Meet the Developers Behind Sonatype’s Malware Detection
- How to Add Additional Source Folders to Your Maven Build
- Best Practices for Tools That Depend on Central Maven Repository
- SSL Connectivity Underway for All Central Repository Users
- Strengthen Financial Resilience: Navigating DORA Compliance
- Sonatype Password Security: Trillion Trillion Trillion Centuries
- Enhance Nexus Repository with OSGi Bundle Repository Support
- Breaking Bad: DevOpsSec to DevSecOps
- Maven Central: New Design and Safety Features for Developers
- Enhancing System Resiliency with Observability Insights
- New in Sonatype Nexus Repository 3.25: Switching to NuGet V3
- Explore Maven Settings Password Encryption Feature | Sonatype
- GitLab: Instant, Inline, Indispensable Developer Insights
- Explore Spring, Maven, and Nexus Best Practices | Sonatype
- 2025 Security Industry Predictions: Embracing Change
- Optimizing Software Supply Chains with Nexus Repository
- How to Browse Javadoc for Dependencies in Eclipse (m2eclipse)
- Best Practices to Enhance Software Supply Chain Security
- Meet an Open Source Contributor: Paul Horton
- 5 Ways Your Organization Benefits From DevSecOps
- Nexus and Maven Highlights: Insights from October 2009
- Explore Nexus Plugin API | Sonatype Blog
- JSR330 Support: Hudson Plugins, Meet Dependency Injection
- Modernize DoD Software Procurement: Role of SBOMs in SWFT
- Intuit's DevSecOps: War Games, Gamification, and Culture Hacking
- World Open Source Day: What We Learned
- Managing OSS Licenses: Avoiding Risks with Sonatype Lifecycle
- Request for Comments: CARE and Maven Central
- Nexus OSS Meets NuGet
- Announcing the Winners of the Sonatype 2022 Elevate Awards
- Top Tips to Consider When Evaluating OSS Logistics Solutions
- Unveiling the Trillion Dollar Engine of Innovation | ADDO
- Sonatype Lifecycle Enhancements Deliver Faster Remediation
- Empowering Developers with Automated Time-Based Waivers
- Sonatype Spots CursedGrabber Packages in New Malware Campaign
- New Sonatype Scan Gradle Plugin: Secure Your Dependencies
- Secure Your Golang Dependencies with Nancy for Docker
- Mastering Dependency Scanning: Mitigate Open Source Risks
- Why Dependency Confusion Attacks Persist | Sonatype
- 20 Essential DevSecOps Reference Architectures | Sonatype
- Optimizing DevOps with Containers: Considerations for Success
- How to Get Started With Sonatype Nexus Repository OSS
- Nexus Support Team Answers Questions on Repository Management
- 40 DevSecOps Reference Architectures to Learn From
- Golden Pull Requests: Automated Remediation, No Breaking Changes
- Introducing Sonatype DepShield: Free for GitHub Developers
- How to Upskill Your Team With Kubernetes
- Counterfeit npm Packages Targeting Developers | Sonatype
- Understanding Scala: The Language Powering Twitter and LinkedIn
- 2025 Predictions: Navigating Compliance & Cyber Regulations
- HID Global's 3 Pillars for Application Security | Sonatype
- Streamline PCI DSS 4.0 Transition with Sonatype SBOM Manager
- Modernizing Nexus Repository: Moving Beyond OrientDB
- Critical Java Vulnerability in pac4j: CVE-2026-29000 Explained
- Alexa: What's the future of cybersecurity? | Sonatype Blog
- Sonatype's Webinar Series: Future Cybersecurity Requirements
- Deploy to Sonatype Nexus Repository with Maven | Sonatype
- Contrasting Nexus and Artifactory | Sonatype Blog
- Cybersecurity Liability | SEC Charges Against Solarwinds
- CVE-2021-22114: Spring-Integration-Zip Path Traversal
- How to Contribute to the Maven Books | Sonatype Blog
- How to Respond to the Hijacked eslint-scope Packages
- Optimizing Security and Efficiency with Sonatype Lifecycle
- Critical Vulnerability in Bouncy Castle: CVE-2018-5382
- Simplify Cybersecurity: The OWASP Vulnerability Management
- How to Access Maven Central with REST API | Sonatype
- Women in Cybersecurity: Career Advice & Insights | Sonatype
- Secure Coding with OWASP Security Knowledge Framework
- Mapping the JavaScript Genome for DevOps
- Understanding the OWASP Top 10: Essential Web Security Risks
- Selecting OSS Software: 10 Questions for Nexus Repository
- Faker npm Library Gets New Home After Dev Quits | Sonatype
- Streamline Dependency Management: Sonatype IQ with Webpack
- DevSecOps Community Survey: Meet the Winner
- Bladeroid Malware: npm Packages Spread Crypto-Stealer
- All Day DevOps Conference: Bringing DevOps to the World
- Automating the automation tools at Capital One | Sonatype Blog
- VMware VSphere Dependency Confusion Thwarted by Sonatype
- Use Sonatype for DevOps and Put the Puppet in a Box
- How to Design Teams to Bridge the Security Gap
- Sonatype's Commitment to Customers and Employees During COVID-19
- DevOps Culture: The Neuroscience of Behavior
- The Future of Dependency Management in an AI-Driven SDLC | Sonatype
- Nexus 2.3 Now Available: Includes Support for Yum
- Is Your Company Prepared for Software Liability Regulations?
- Maven 3.0: Resolving Core Issues + Enhancing Build Processes
- $3M Cryptocurrency Heist Stemmed from a Malicious GitHub Commit
- Sonatype Nexus Repository Is Rising Above the Swamp
- Introducing a Free Nexus Repository Community Edition
- New in Nexus Repository: Enhanced Support and New Features
- Nexus Repository 2.1: Fueled by Unicorns With Jet Packs
- Why the World's Vulnerability Index Cannot Keep Up
- The ultimate Java build system | Sonatype blog
- Sonatype Nexus Repository and Helm for CI/CD | How-To Guide
- Why Software Supply Hygiene Matters: Exploring a Legal Case
- Cheeseburger Risk: Not for the Faint of Heart
- Why Developer Experience Is the Foundation of DevSecOps Success
- DevSecOps Essentials: Integrating Security into the SDLC
- The Mythos AI Vulnerability Storm: What to Do Next
- Proxying Conda Repositories with Sonatype Nexus Repository
- Software Supply Chain Security Inside and Out | Sonatype
- We're Bringing Sexy Back, Sonatype Hits the Catwalk
- Explore Sonatype Nexus Security Advisory | Sonatype Blog
- Malware Monthly: Exploring Open Source Threats and Cyber Risks
- Explore CISA's 2025 SBOM Minimum Elements | Federal Agencies
- Testing Nexus With Selenium: A Lesson in Complex UI Testing
- Mitigating Zero-Day Vulnerabilities: Guide for DevOps Teams
- Malicious PyTorch Lightning Packages Found on PyPI
- Defend Against Trojan Unicode Attacks | Firewall
- DevSecOps Goes Mainstream
- Maven IDE and Eclipse: A New Era of Seamless Integration
- SANDWORM_MODE: Rise of Adaptive Supply Chain Worms in Ecosystems
- Integrating SBOMs into Your Software Development Life Cycle
- Using Sonatype Nexus Repository 3: Docker Images | Sonatype
- Sonatype Nexus Repository Docker Installation Guide
- Discord Patches Critical Electron Bugs Amid Rising Attacks
- Integrating Maven 3 with Sonar | Sonatype
- Application Security Needs to Be Redefined to Stay Relevant
- Building Open Source Management into Software Development
- Maven Central Repository Traffic: Using S3 | Sonatype Blog
- How to Use Nancy to Improve Your Go Application Security
- Nexus Reaches 50,000
- Now Playing: Grails 1.1b2 with Improved Maven Support
- Reinventing Wheels and Opportunity Cost | Why You Need Nexus
- How a Software Bill of Materials Uncovers Known Vulnerabilities
- Secure, Reliable Terraform At Scale With Sonatype Nexus Repository
- Maven 3.0-alpha-3 Released | Sonatype Blog
- Hear no evil, see no evil, deploy no evil | Sonatype blog
- Enhancing Maven Central: Improving Quality and Accelerating Access
- Gitpaste-12: Exploits on GitHub, Attacked Linux Servers
- Integrating Nexus Indexer API: Indexing Maven Repositories Made Easy
- Cybersecurity Predictions 2025: AI Malware Trends | Sonatype
- 450 Packages and Phishing Campaign against PyPI Maintainers
- Malicious Roblox and Discord Token Stealers Found on PyPI
- DevSecOps Maturity Model: Complete Security Practices Guide
- DevOps Express: How it happened and why we did it | Sonatype Blog
- Block Vulnerable Open Source Artifacts | Repository Firewall
- DevSecOps: Better Software, Faster
- OWASP Top 10: Navigating AI Risks in Application Security
- Rubyists Rejoice: Sonatype Nexus Repository Support RubyGems
- Exploring the 9th State of the Software Supply Chain Report
- Sonatype CEO on DevOps Maturity and DevSecOps Beginnings
- Federal DevSecOps Leaders: It's Time to Join the Conversation
- Why DevOps Advocates Are Implementing Shift Left Testing
- Securing Software Supply Chains: U.S. Government Guidelines
- The Central Repository Supports Sailors from Bintray | Blog
- Overcome New Docker Hub Rate Limits with Nexus Repository
- DevOps Radio Podcast: The Story Behind All Day DevOps
- Q2 2026 Open Source Malware Index
- Wicked Good Development: State of the Software Supply Chain
- Compromised litellm PyPI Package Exposes AI Systems
- Deploying Third-Party JARs to Maven Repositories with Ease
- How to Create a Nexus Plugin Using m2eclipse in Eclipse
- Sonatype a Recognized Cybersecurity, DevOps Tech Titan
- Spring4Shell: Understanding the Impact and Response
- Comparing npm Audit vs AuditJS for JavaScript Projects
- What I Learned From DevSecOps Leaders in a High-Tech World
- Detecting Snapshot Versions in Maven Projects | Sonatype
- Update CVE-2019-7238 in Sonatype Nexus Repository
- 26% Acknowledge a Web Application Breach in 2019
- Developers are the New Security Perimeter | Shadow Downloads
- When Cyber Attack Meets Heart Attack | Sonatype Blog
- Pipeline Security: Open Source Malware Prevention | Sonatype
- DevOps Made of Steel
- A Year of Providing Free Maven Repository Hosting | Sonatype Blog
- AI and Malware: Infiltrating Software Development Teams
- DevOps success is contingent on shifting left | Sonatype blog
- Illicit PyPI Packages 'Netfetcher' & 'Pyfetcher' on Windows
- Chevy and DevOps: What the Wi-Fi?
- How AI Governance Reduces Risk in Software Supply Chain Security
- Nexus Pro and OSS 2.0.6 Now Available with Security Fixes
- Smart Teams Use Atlassian and Sonatype to Plan Development Work
- Blue By Default
- Up Next: Nexus Support for Yum Repositories | Sonatype Blog
- The Dot Zero Conundrum: A New Frontier of Secure Open Source
- Streamlining Flexmojos Integration Testing with Maven Verifier
- RebelLabs Java Survey: Developers Love Nexus Repository
- Securing Software Supply Chains and Dependency Confusion
- Wicked Good Development: Fall 2022 Maven Central Updates
- The Path of DevOps Enlightenment for Infosec | Sonatype Blog
- February News: Updates on Maven and Sonatype Contributions
- Policy and Advanced Component Search With Sonatype Lifecycle
- Jason van Zyl talks to How Software is Built | Sonatype Blog
- Corporation waits until the software flaw trends on Twitter
- State of SBOM: Emerging Standards and Global Regulations
- DevSecOps: Embracing Automation While Letting Go of Tradition
- Improving Build Time of Java Builds on OpenShift
- Skeleton Key
- Enhancing Search Features in Sonatype Nexus Repository 3.14
- Vista acquires a majority interest in Sonatype | Sonatype Blog
- Wait! Wait! Don't pwn me! from Black Hat 2014 | Sonatype Blog
- Running Nexus and Hudson on Amazon EC2: A Quick Start Guide
- Open Source License Management in Finance | Sonatype
- JavaScript Scanning Now Available in JetBrains IDEs
- AI Development Security Risks & Governance | Sonatype
- Secure By Design: Preparing for GDPR Should Begin With Software
- Private npm Registry in Nexus Repository | Sonatype
- Sonatype Firewall Blocks 101K+ Malicious Packages
- An Innovator's Journey: Eight Interviews
- Sonatype Wins Award for Best Open Source DevOps Tool
- Who Is Nigel Simpson? Lessons of Open Source Governance
- npm Malware Mines Cryptocurrency on Multiple OS Platforms
- How to Stop Malware in the Software Supply Chain | Sonatype
- Open Source, Open Infrastructure, and the Space Between
- Bryson Koehler, Equifax CTO, Discusses Data Security Future
- A DevSecOps Maturity Model in Seven Words
- New Beta REST API for Sonatype Nexus Repository: A Deep Dive
- Enhancing DevSecOps: Sonatype Firewall Adds PyPI Support
- Nexus and Maven Highlights: Exploring Developer Insights
- Sonatype CTO Joins Cyber Panel on Financial Compliance
- Exploring Insights on DevSecOps and Container Security
- Why Diversity Shouldn't Be a Vanity Project
- 5,000+ Dependency Confusion Copycats Flooded PyPI and npm
- Nexus 2.11.1 - Why It's Time to Upgrade
- NPM Hijackers Takeover of 'coa' and 'rc' Libraries
- DevSecOps: Integrating Automated Security Controls
- Get Log4j Usage Insights with Sonatype Nexus Repository
- Enhancing Software Security with SCA and SAST Tools
- Explore The Hidden Threat of Malicious OSS Components
- Workflow Automation: Publishing Artifacts to Sonatype Nexus Repository Using Jenkins Pipelines
- 5 Essential Tools to Automate Your SBOM Creation Process
- Sonatype Releases Nexus Repository 3.0
- (CVE-2018-11776): Another New Apache Struts Vulnerability
- Essential Documents for New Contributors to OSS Projects
- How to build a RAP application with Tycho | Sonatype Blog
- A More Secure Web Needs Developers, Defenders, Advocates, and OSS
- Introducing Sonatype CLM: Secure Component Lifecycle Management
- A Newcomer's Perspective: Software Supply Chains
- Free Software, But No Free Lunch
- Dependency Management in Software Development | Sonatype
- Why LLMs Make Terrible Databases and Why That Matters for Trusted AI
- Effortlessly Deploy Sonatype Platform with NGINX and Docker
- Vor Security Brings OSS Index to Sonatype | Sonatype Blog
- DevSecOps: Overcoming the Culture of No's With Chaos
- Lessons in Complex UI Testing | Testing Nexus with Selenium
- DevSecOps Leadership Forum: Revolutionizing Financial Services
- Full Lifecycle Container Security
- Fake VS Code Extension on npm Uses ScreenConnect as Spyware
- Leadership Lessons: Adapting to an All-Remote Workforce
- Malicious npm Packages Exploit Popular 'colors' Library
- Washington Magazine Ranks Sonatype on Best Places to Work
- Can Sonatype Nexus Repository Scale? | Sonatype Blog
- Why DevOps Success Requires More Than X-Ray Vision
- Use JSON? Well You'd Better Not Be Evil | Sonatype Blog
- Disrupt Yourself or Be Disrupted
- How to Retrieve Documentation for Maven Plugins | Sonatype
- White House National Cybersecurity Strategy: Landmark Action
- This Week in Malware - Over 70 Packages Discovered | Sonatype
- A Simply Brilliant Way to Improve the Security Pipeline
- How to Manage Third-Party SNAPSHOT Dependencies in Maven
- Efficiently Scanning for Log4j Vulnerabilities | Sonatype
- Storage Management Best Practices: Part 1 - Components in Motion
- Introducing a Better Way to Learn Sonatype Products
- PyPI Cheese Shop Malware Software Supply Chain Risk
- Malware Wrap-up: npm Backdoors, Bugs, Mystery Placeholders
- How to Publish Private npm Packages to Sonatype Nexus Repository
- Enhanced Support for Python in Sonatype Lifecycle
- Accelerate DevOps With Sonatype's Multi-Product AWS Offering
- Prototype Pollution Vulnerability in express-fileupload
- Let Your Voice Be Heard: Take the DevSecOps Community Survey
- Mitigating Risks with Open Source AI Governance | Sonatype
- Manage and Eliminate Technical Debt for Increased Innovation
- Insights on Hosted Repositories Capacity in Nexus OSS
- A Sort of a Homecoming - Why I Joined Sonatype
- Sonatype + Muse: How Improved Code Quality Complements SAST
- Lessons Learned from the FOSS/PLG Journey at Sonatype
- Sonatype Training Courses and Self-Paced Guides | Sonatype
- Trojanized PyPI Package Imitates a Popular Python Server Library
- Caroling through the Season: The Sounds of the 4shells
- The Path Forward for the Sonatype Platform | Sonatype
- Maven and GitHub Integration: A Guide for New Projects
- Embracing the AI Revolution: Navigating the Impact on Developers
- Maven and Nexus Updates: Developer Community Highlights
- Navigating Complex OSS Licensing: Lessons from Meteor and MongoDB
- March Malware Monthly: Info-Stealers, Reverse Shells, and Data Leaks
- To Succeed, DevSecOps Must Actually Include DevOps | Sonatype
- Securing LLM Outputs: Strategies for Safe AI Integration
- Security Isn't Just for AppSec: Why Developers Must Care
- Dogfooding Nexus
- Maven Central: Addressing the Tragedy of the Commons
- Using Sonatype Nexus Repository 3: npm Packages | Sonatype
- Special Character Encoding Properties in Maven | Sonatype
- PyPI Malicious Packages: 1K+ Flood the Registry | Sonatype
- Ensuring Compliance with Open Source License Management
- The Open Source Software Index Is BOSS | Sonatype
- From a Commodore 64 to DevSecOps
- npm Malware Exfiltrates Windows SAM, Amazon EC2 Credentials
- DevOps: The Blue Ocean Tide Is Rising
- easy-day-js Targets Mastra, Dependency Attacks Grow
- Understanding Application-Level Package Managers | Guide
- New in Sonatype Nexus Repository 1.6: Key Features and Updates
- How to Upskill Your DevOps
- Automating Open Source Dependency Management | Sonatype
- DevSecOps: Eat Carrots, Not Cupcakes
- Master Plexus Container: A Guide to Dependency Injection
- Securing Vulnerabilities in Jenkins Pipelines | Sonatype
- Publishing Your Open Source Artifacts to the Central Repository
- Crypto Enthusiasts Flood npm with 281,000 Fake Packages
- In the Dark About Software Supply Chain Vulnerabilities
- Sonatype Closes $30 Million Financing
- Brazen DNS-Based Attack: Hacker Steals $12,000 in Bitcoin
- FlexMojos Focus on 0.5 Maven Book Release | Sonatype
- From Chaos to Control: Establish an OSPO for Strategic Governance
- 2016 State of Software Supply Chain Report Insights | Sonatype
- The Magic of a Remote Organization | Sonatype Blog
- Sonatype Eliminates Pain of Reporting OSS Vulnerabilities
- DevOps Intelligence Changes the Game
- Ken D'Auria's DevSecOps Journey at The Hartford Innovator
- Outpace Malware: Secure Software with Real-Time Protection
- How Delta Air Lines Rolled Out Nexus Across the Enterprise
- npm Chalk and Debug Packages Compromised | Sonatype
- From Burping to Flying - Red Teaming With Sonatype At Intuit
- Sonatype Named in 2023 Gartner Magic Quadrant for AST
- Enhancing Hudson with JSR-330: Simplifying Developer Workflow
- Breaking Organizational Silos for Better Application Security
- New npm PoC Packages Exploit Dependency Confusion | Sonatype
- How Achievers Transformed DevOps with Sonatype
- Improving Test Coverage Reports for Integration Tests with Maven
- Open Source Malware Trends: Q1 2025 Malware Index | Sonatype
- CMMC 2.0 in Action: Operationalizing Secure Software Practices Across the Defense Industrial Base
- Grounded Intelligence Ensures Safe AI Software Development
- Overcoming Common Myths About Continuous Delivery
- The People Behind Sonatype: Sue Jasmin
- New Official Maven Central Repository in Europe | Sonatype Blog
- Beta version of Nexus Book ePub now available | Sonatype Blog
- A Perspective on Sonatype's Road to Continuous Delivery
- Migrating from Plexus to Guice: Crafting a Guice Bean Extension Layer
- Advanced Maven Reactor Options for Multi-Module Builds
- Explore New Policy-Oriented Reports in Sonatype Lifecycle
- Promise Theory and DevOps | Sonatype Blog
- Sonatype Nexus Repository 2.1.2: New Enhancements Released
- Does Nexus support Ant + Ivy builds? Yes it does | Sonatype Blog
- New Sonatype Nexus Repository 1.5.0: LDAP, Archive Browsing, Javadoc
- Sonatype Firewall Shields Against OSS Invasions
- Sonatype Lifecycle Report Redesign Survey | Sonatype
- Benefits of a Repository Manager: Partners and Vendors
- ABN AMRO Embraced CI/CD for Better Innovation and Security
- Developers: We Must Evolve
- Antoine Harden Joins Sonatype as RVP of Federal | Sonatype
- Maximizing Value with Sonatype Lifecycle's Success Metrics
- Air-Gapped Software Security: Offline Environments | Sonatype
- Maven 3 Plugin Configuration for Developers and Users | Sonatype
- DevSecOps: Dreams, Teams, and Architecture
- Securing Mobile Apps with Dart, Flutter, and Sonatype
- Useful Docker Images – Part 1 | Sonatype
- 2020 International Women's Day Theme Resonates in DevSecOps
- Setting Boundaries: How Procurement Relates to Security (Part 1)
- How-To Video Training: Open Source Component Management
- Protect Against Hijacking with Nexus Repository Routing
- What You Should Know About the Latest Struts2 Vulnerability
- Securing the Software Supply Chain: CISA Best Practices
- Mitigating Open Source Persistent Risks in Software Security
- Encrypting Passwords in Maven: A Step-by-Step Guide
- Learn What Is Spring4Shell? | Wicked Good Development
- Apache Tomcat Vulnerability: Nearly 100K Risky Downloads
- Enhance Security with Continuous Compliance and DevOps
- New Malware: Python Crypto & Dependency Confusion Packages
- On Maven model transforms and C# | Sonatype blog
- Getting rugged DevOps right | Sonatype Blog
- CVE-2020-13935: Apache Tomcat WebSocket DoS Vulnerability
- Breaking Builds and Securing Code: Insights from ABN AMRO
- RSAC 2018 - The opening session for DevOps Connect: DevSecOps Day
- The Evolution of Maven Central: From Origin to Modernization
- Exploring Distributed Continuous Integration with Hudson | Sonatype
- New Typosquats in PyPI, Dependency Confusion Packages
- Software Packages, Do We Even Need Them?
- Struts Vulnerabilities Persist: Are You Ignoring the Risks?
- Why Open Source Matters and How Companies Can Contribute
- Explore The Persistence of OSS Vulnerabilities and Avoidable Risk
- Temp IP Change to Improve Maven Central Failover Mechanism
- How DevOps Killed the Market for Software Composition Analysis
- Sonatype Nexus Innovator: Bloomberg Industry Group
- Why Sonatype Is Acquiring MuseDev
- Talking Turkey in Texas: Open Source Governance Lags
- Securing Software Supply Chains: Sonatype's Firewall Policy
- WSJ on Struts: Companies Still Downloading Vulnerability
- Managing AI Risks in the Modern Software Supply Chain
- What's New in Sonatype Nexus Repository Open Source 1.7.0?
- Maven: The Complete Reference is Now Available as An Epub
- Optimizing Platform Health with Synthetic Monitoring
- Detect and Mitigate the Discord.dll Malware Threat in npm
- TED Talks security: Three provoking discussions | Sonatype Blog
- A Struts2 Vulnerability Hurricane: Deserialization
- m2e Roadmap | Sonatype Blog
- Fannie Mae: Scaling the DevOps Enterprise
- Sonatype's Enterprise Development Survey | Sonatype Blog
- Understanding Hashing: Key to Unique Identifiers in Software
- Bryan Batty on the Importance of Open Source Governance
- This Week in Malware - Nearly 40 Packages Discovered | Sonatype
- PyPI Attack: 1,275 Dependency Confusion Packages Detected
- SAST vs. DAST: Enhancing Application Security in DevSecOps
- See Why Happy Developers Produce More Secure Software
- Mastering SBOMs: Demonstrations
- Optimizing Maven Projects: Using the Dependency Plugin
- npm Ransomware Attack: Malicious npm Package | Sonatype
- Replacing the Release Process Using the Staging Suite
- Access OSS Project Download Stats on Maven Central | Sonatype
- Open Source Components, a Fine Vintage or Sour Milk?
- Devs Flood npm with 15K Packages to Receive Tea tokens
- Future of Open Source: Navigate the Cyber Resilience Act
- Sonatype Lifecycle + Microsoft Visual Studio Integration
- DevOps Assurance With OWASP SAMM
- Malicious npm Packages Conceal macOS Malware in Travis CI
- How To Merge Sub-Items From Parent to Child POM in a Maven
- Essential DevSecOps Tools for Secure Software Development
- Enhancing Security with SBOMs and Continuous Monitoring
- npm Package Everything Sparks Controversy | Sonatype
- Building Trusted AI Development With Kiro and Sonatype Guide
- The Unchanging Laws of Software in the Age of AI | Sonatype
- Security Should Stop Being a Drag
- 3 Reason Why I'm Excited for Red Hat Summit
- Two AppSec Questions Always Asked
- Why External Repos Are Being Phased Out of Maven Central
- Often you people are too smart to train | Sonatype blog
- Sonatype Goes to CloudBees Days
- Nexus: Don't Dive in Until You Know How to Swim
- Developers Need The Sonatype Platform and Pot of Coffee
- What's in Your jQuery App? Not the Fishy 'jquery-lh' We Hope
- Software Composition Analysis: Precision Definitely Matters
- OSS Projects Affected by HTTP/2 'Rapid Reset' Vulnerability
- IndonesianFoods Malware: Open Source Worm | Sonatype
- DevSecOps: Security at the Speed of DevOps
- Next Generation Maven Development Stack Unveiled at JFokus
- How to Onboard Sonatype Lifecycle via Source Control
- A DevSecOps Journey at a Dutch Bank
- Latest Updates to the DevSecOps Reference Architecture
- m2eclipse 0.9.8 Dev Build Available | Sonatype Blog
- What Developers Need to Know About WhatsApp Security Issues
- Cybersecurity Awareness Month: Developers Are Our Guardians
- New Developer Enhancements in Sonatype Repository Firewall
- Managing OSS Legal Compliance With Advanced Legal Pack
- Component-Capable Release Management: The Key to Successful DevOps
- That's billion with a B: Is Java having an Outlook moment?
- SSO/SAML Authentication and Conan Support in Sonatype Nexus
- Clean Up Old Docker Images From Sonatype Nexus Repository
- A Lesson in Why Security by Press Release Is Detrimental
- Red Hat Summit is a quality choice | Sonatype Blog
- Part 2 - [ ________ ] Is the Best Policy
- Sonatype Nexus Reference Platform: Docker Stack & Kubernetes
- DevSecOps and Chaos Engineering: Knowing the Unknown
- Understanding Repository Managers: Key Features and Benefits
- Exploring Application Security Risk in 2019 | Sonatype
- Nexus Repository Manager 3.8 Released with Yum Support
- New Tool for Effortless Artifact Search in Maven Central
- Exploring How Sonatype Nexus Repository 1.3 Works
- Publishing artifacts with Nexus Repository and Apache Ivy
- CIO.com: Helping Developers Reduce Open Source Risk
- Key Insights from the Gartner Security and Risk Management Summit
- Best Practices for Securing Open Source Code Quality
- CVE-2024-3094: Backdoor Attack Against xz and liblzma
- How to Disable Redeployment in Sonatype Nexus Repository
- Nigel's Wake-up Call: Scaling Open Source Governance
- Update on CVE-2019-7238: Ensuring Your Nexus Repository is Secure
- Software Supply Chains: Reject, Replace, and Respond
- Wicked Good Development Episode 32: Java Queens at Devnexus 2023
- Wicked Good Development: Exploring Open Source Compliance
- OpenShift CI/CD Pipelines with Jenkins | Sonatype
- What Golden Dome Requires from Federal DevSecOps Teams | Sonatype
- Optimal Maven Plugin Configuration | Sonatype Blog
- Sonatype Partners With ADDO on Largest DevOps Conference
- DevOps Enhances Cybersecurity in Federal IT Systems
- Ready to Take the Two-Minute Nexus Challenge? | Sonatype
- Technology Preview of Sonatype Nexus Repository 3.0
- Boost Open Source Security with Sonatype Lifecycle
- Crypto npm Malware: Hijacked npm Packages | Sonatype
- Sharing Resources Across Maven Projects: Step-by-Step Guide
- Understanding Maven Dependency Resolution | Sonatype
- DevSecOps and GDPR: Why Open Source Risk Management is Important
- A Time for Cyber Supply Chain Management in Congress: Part 2
- CVE-2020-2100: Jenkins UDP Amplification Reflection Attack
- The Rise of Dependency Scanners | Sonatype
- An Interview with Brian Fox: Maven 3, Central, and Nexus
- AI/ML Insights That Safeguard Developers from Malware Threats
- The 2015 State of the Software Supply Chain Report
- Cloud Security Concerns in 2021
- Is Your Repository Ready for What's Next?
- Understanding Nexus Tasks for Optimal Repository Management
- Nexus Repository Now Supports APT Repositories | Sonatype
- Explore New Cloud-Native CI/CD Projects | Sonatype
- Use Staging Repositories for Quality Deployment in Nexus
- Open Source Growth: Benefits and Security Challenges
- Documenting Nexus REST API with Enunciate: A Developer's Guide
- Dirty Rivers Flow Downstream, Leading to Dirty Reservoirs
- Sonatype Celebrates World Open Source Day 2023
- ZeroTrustOps: Securing at Scale
- Cross-Platform Backdoor Found in 'cors-parser' npm Package
- Why Developers Are the Weakest Link in Supply Chain Attacks
- Identify Open Source Vulnerabilities with Sonatype OSS Index
- Meet Ankita Lamba: Values Champion
- Information Stealer Malware: Cybercrime Market | Sonatype
- John Deere Dependency Confusion Attempt Flagged by Sonatype
- PhantomRaven: npm Malware Uses Remote Dynamic Dependencies
- Software Dependency Cooldowns Are a Symptom, Not a Strategy
- Transitioning Software Supply Chain Management to the Cloud
- CALMS Framework: The Key to Successful DevOps Transformation
- Understanding NIS2: The Scope, Requirements, and Impact
- Maven Training Insights: Checksums, SSH Keys, and Writing Plugins
- Debunking CVE-2022-31289: A Misunderstood Security Flaw
- Open Source Attacks: OSS Threats on the Uptick | Sonatype
- Kubernetes in 10 Seconds
- How SLSA Enhances Software Supply Chain Security | Sonatype
- Best Practices in Provisioning Sonatype Nexus Repository
- Publishing Artifacts to the Central Repository | Sonatype
- Enhancing Financial Software Security with Sonatype and AWS
- SBOM Manager New Features Accelerate Compliance and Security
- Deterministic DevSecOps: Best Practices | Sonatype
- Build Better Component Practices: Crawl, Walk, Run
- "WTF Is DevSecOps?"
- m2eclipse 0.9.5 Release: Exploring the POM Editor | Sonatype
- Building a Docker Registry with High Availability on AWS
- How to Optimize Modular Maven Projects with Nexus | Sonatype
- Sonatype's Role in Strengthening the Maven Community and Ecosystem
- Deploy Secure Applications With DevOps, DevSecOps
- Securing the AI Era: Sonatype Safeguards Open Source Software Supply Chains
- Sonatype Named Leader in Forrester Wave™ for SCA | Sonatype
- Congress Pushes for Cybersecurity with Software Bill of Materials
- Explore Why Sonatype Nexus Repository For Non-programmers
- What is DevSecOps? How to Integrate Security in DevOps Practices
- DevSecOps for a Dollar or Less
- PayPal's Strategy for Remediating Critical Software Vulnerabilities
- Apache Struts2 (S2-053): How One Developer Braces for Impact
- Sonatype Recognized as a Leader in SCA by Forrester
- NIST: Adopt a Secure Software Development Framework (SSDF)
- Automate SBOM Reporting for U.S. Army Compliance | Sonatype
- Rugged DevOps: Survival Is Not Mandatory
- Continuous Delivery: Overcoming Common Objections
- Nexus Plugins Integration Testing: Best Practices and Tools
- Create Two JARs from One Project: Best Practices & Pitfalls
- Sonatype Guide: Giving AI the Context It Needs
- Understanding the Sonatype Safety Rating for OSS Projects
- Explore Maven Central Performance Improvements With Edgecast
- Fallguys Malware Targets Browsing Data and Discord IMs
- New in Nexus Repository: R Format and VS Code Support
- The Rise of Collective Defense for Open Source
- Explore How Sonatype Leads in SBOM Management and Visibility
- NeuVector and Lifecycle Integration: Securing Containers
- Automating Staging Workflow With Gradle and Nexus Repository
- Explore Aether: The Embeddable Maven Repository API
- DevOps Leadership Series: Monitoring Containers and Microservices
- Part 3 – [ ________ ] Is the Best Policy
- Sonatype Lifecycle Integrates with Azure DevOps | Sonatype
- Maintainer Sabotages npm Libraries 'colors' and 'faker'
- Accelerate DevOps: Key Practices for High-Performing Teams
- Releasing the Apache Maven-Bundle-Plugin 2.2.0
- Exploring Key Benefits of Integrating Sonatype with Your IDE
- Transform Enterprises: Leadership Insights on Generative AI
- DevOps Confessions From Fannie Mae, Capital One, and More
- CVE-2023-50164: Apache Struts2 Vulnerability | Sonatype
- GDPR and OSS. How Are They Linked and Why Should You Care?
- Maven Central Repository Moves to HTTPS for Better Security
- A Guide to Migrating from Apache Archiva to Sonatype Nexus
- What the TPG-led $80M investment means for the future of Sonatype
- Why Sonatype Nexus Repository Rocketed Beyond 60,000 Installs
- Improve Your Supply Chain with a Software Security Framework
- Unlock Efficiency in Software Management with SBOMs
- Mitigating OSS Risks: Insights from the ISACA Journal
- Taking on the Ultimate Challenge: Deca Ironman for Charity
- Java Serialization - The Gift That Keeps on Taking (Part 1)
- OpenSSF Calls for Multifaceted Software ID Strategy
- How AWS Enhances Sonatype's On-Demand Training Infrastructure
- 5 Steps to Turn Your RMF Backlog Into a Continuous ATO: The CSRMC Migration Playbook
- Next-Gen Build Tools for Eclipse Plugins & RCP Applications
- Wicked Good Development: Cybersecurity Experts Talk Log4j
- Navigate EU Cyber Resilience Act Compliance | Checklist
- Model Context Protocol (MCP) & AI Workflows | Sonatype
- The Big Hack: Chinese Military Implicated in Equifax Breach
- Software Composition Analysis: A Matter of Perspective
- Federal Software Security Demands Velocity and Assurance
- CVE-2014-3603: Lack of Hostname Verification in OpenSAML
- Continuous Delivery: The Atlassian Way
- Securing and Scaling InnerSource With Automation
- Scaling Infrastructure Management with Terraform | Sonatype
- Malicious 'Distutil' and Spring4Shell Active Exploitation
- From 0 to Accredited in 23 Days
- Evolving Developer Roles: Beyond Just Coding | Sonatype
- Enhancing DoD DevSecOps: Key Takeaways & Sonatype Alignment
- Explore Guardrails for Safer AI-Assisted Software Development
- Salesforce Transforms Open Source Approval with Automation
- 10 reasons why All Day DevOps 2017 is awesome | Sonatype Blog
- Over 50 Malicious Packages Identified This Week | Sonatype
- Wicked Good Development: James McLeod's Journey to FINOS
- Why Software Supply Chain Security Requires a New Playbook
- Insecure at Any Speed
- The Top 5 Trends Every CISO Needs to Know | Sonatype
- Ghostcat CVE-2020-1938 Vulnerability: Critical Apache Tomcat
- How to Get Started With Sonatype Nexus Repository REST APIs
- Log4j Exploits Are Now Being Used to Spread Dridex Banking Trojan
- npm Malware: Bladabindi Trojan in Typosquatting Packages
- Explore Nexus Repository 1.3 New Mirror Support Feature
- Sonatype Lifecycle Enhancements Boost Speed and Security
- Malicious 'pymafka' Package Drops Cobalt Strike | Sonatype
- AI is Hard Work: Unveiling the Real Effort Behind the Hype
- The Central Repository Is Getting Faster. Ready for New IPs?
- Software Supply Chain Maturity Model & Assessment | Sonatype
- Meet an Open Source Developer: Theresa Mammarella
- Shai-Hulud is Back: Maintainer Accounts Are Still the Soft Target
- Essential Role of SBOMs in Cybersecurity and Compliance
- The Cybersecurity Improvement Act: A Legislative Legacy and Future
- PyPI Crypto-Stealer Targets Windows Users in New Campaign
- Debunking DevSecOps Myths | Sonatype
- Simplifying SBOMs and Enhancing Security with VEX | Sonatype
- Hudson's bright future | Sonatype blog
- Maven 2.0.10 Released | Sonatype Blog
- Achieving a Managed State Model for Your Software Supply Chain
- Meet an Open Source Contributor: Sal Kimmich
- Explore Sonatype Nexus Repository Roles and User Permissions
- Software Governance in Air-Gapped Environments | Sonatype
- Insights from Bryan Batty on Security Experimentation and Metrics
- Open Source Governance: Why It's Crucial for Executives
- Replace Plain Text Credentials With User Tokens | Challenge
- Now Available: SSL Connectivity to Central | Sonatype Blog
- Discover The Top 5 Tomcat Vulnerabilities | Sonatype Blog
- (ISC)² Global InfoSec Study on Application Vulnerabilities
- Nexus Repository 3.7.0: Introducing Hierarchical Browsing
- Navigating Docker Hub Rate Limits with Nexus Repository
- Extended Sonatype Firewall Support for RubyGems and RPM
- Helm and Nexus: Accelerate Deployments with Nexus Repository
- Cancer Sucks, DevOps Helps
- The Sonatype 2014 Engineering Summit | Sonatype Blog
- Critical Security Alert: CVE-2018-16487 in Lodash Library
- AI Predictions 2025: Artificial Intelligence Trends | Sonatype
- Sonatype Nexus Repository 2.0.5 Release: Explore Features
- Continuous Integration with Containers in CI/CD Pipelines
- Ivanti Connect SSRF Vulnerability Traced to 'xmltooling'
- Spring Security Vulnerability CVE-2021-22119 | Sonatype
- Malicious Attacks on Open Source Are Going to Get Worse
- Understanding the Critical Struts2 Security Vulnerability
- Sonatype-2018-0413, flatmap-stream's back, back again | Sonatype
- Hitting the Trifecta With GitLab Automated Merge Requests
- Rework Is Choking Software According to Sonatype Report
- Open Source Evolution: Key Lessons from the Last Decade
- Bryan Batty von der Bloomberg Industry Group, Teil 2
- The Power of Generative AI in Software Development | Sonatype
- Sonatype Lifecycle and IntelliJ IDEA | Sonatype Blog
- Exploring The Anatomy of RubyGems 'rest-client' Hack
- Understanding Software Bill of Materials (SBOM) | Sonatype
- What Differentiates Nexus Repository Manager? | Sonatype
- Getting Started With Sonatype Vulnerability Scanner
- Maven How-To: Merging Plugin Configuration in Complex Projects
- DevSecOps, Germs, and Steel: Tales From 5,558 Pros
- Integrating Sonatype CLM with SonarQube for Code Quality
- Sonatype Nexus Repository and Yum Hosted Support
- Sonatype's Commitment to Advancing Hudson and Making Great Software
- Open source changes fast. Can you keep up? | Sonatype Blog
- Explore New Navigation Improvements in m2eclipse XML POM Editor
- Fix Vulnerabilities with GitHub PR Reviews & Line Comments
- Sonatype a Cybersecurity Impact Award Honoree
- DevSecOps: The Carrot and the Stick
- Securing the AI Stack for Federal Missions
- Maven tips and tricks: Describing Maven plugins | Sonatype Blog
- Miasma Returns: Leo Platform Compromise in npm
- GDPR Gets Teeth: British Airways and Marriott Fined
- Nexus Repository: Auto-Blocking Unreachable Repositories
- How We're Staying Connected with Our Channel Partners
- Maven Central Supports TLS 1.2 Only
- Crypto-Mining: Why Software Supply Chain Hygiene Matters
- Can Kubernetes Keep a Secret?
- Simplify Policy Oversight: New Notifier Plugin for Bitbucket
- Simplify NIS2 Compliance with Sonatype's Comprehensive Guide
- Learn the 2.x REST API: Automating Sonatype Nexus Repository
- PCI 3.0: The Importance of Secure Components in Payment Systems
- Key Trends in Application Security: AI, DevSecOps, and SBOMs
- Preventing Vulnerabilities with Lessons from HeartBleed Bug
- January Malware Monthly: Major Threats in Software Supply Chains
- Celebrating $100m in ARR and Welcoming Our First President
- New in Sonatype Nexus Repository 3.24: Storage Optimization
- How Jasmine James Rolled Out Nexus at Delta Airlines
- JavaScript Security: Nexus Repository Introduces npm Audit
- What Enterprise Architects Can Learn from Time Travelers
- Agile, Component Development, and DevOps: A Natural Match
- Lottie Player Compromised in Supply Chain Attack | Sonatype
- Fixing a Vulnerability? Ensure GitHub Isn't Showing Too Much
- From Plexus to Guice (#1): Why Guice? | Sonatype Blog
- How to Use Sonatype Nexus Repository with Maven Deploy
- A point of inspiration | Sonatype employee insights
- Navigate Australia's ISM Guidelines for Secure Development
- Do You View Your AppSec Tools As an Inhibitor to Innovation?
- Sonatype Firewall: Perimeter Defense for Repositories
- Malicious npm Packages Expose Sensitive User Information
- Developers Gain Feedback with Automated Pull Requests
- Lessons Learned Again #npmgate
- A Tale of Two SDLCs: Rise of the AI-Powered SDLC
- Kubernetes Containers a Boon for Developers
- Aether Questions Answered for JAX | Sonatype Blog
- Understanding Software Supply Chain Attacks & Key Incidents
- DevSecOps Tools to Build a Security-Minded Development Team
- Mastering Complex UI Testing: Selenium Strategies for Nexus
- OWASP Top 10: Insights from Caroline Wong | Sonatype
- Managing 5,000 Jobs in Jenkins: DevOps Best Practices
- Detect Malicious Packages to Secure Software Supply Chains
- When It Comes to Application Security, Knowledge Matters
- Sonatype Platform: 2019 Key Features and Enhancements Recap
- Modern Vulnerability Management in the Age of AI
- Sonatype Thwarts Major Software Supply Chain Attack
- Simplifying Policy Management with Sonatype CLM 1.5 Release
- Nexus Wins in an Objective Comparison of Repository Managers
- For Distributed Teams, It's Not All About the Tools
- Mastering SBOMs: Best Practices
- This Week in Malware - July 15th Edition | Sonatype Blog
- Russian Hacker Sells 250+ Malicious npm Packages on Telegram
- Malicious PyPI Package VMConnect Imitates VMware vSphere
- Efficient Interaction With the Central Maven Repository
- Anatomy of a Continuous Delivery Pipeline
- Oracle Issues Critical Security Bug Fixes for Databases
- Meet an Open Source Contributor: Jeffry Hesse
- Switching from SVN to Git: A Comprehensive Guide
- Enable Automated Pull Requests in Atlassian Bitbucket
- DevOps Requires an Optimized Application Delivery Tool Chain
- Empowering Women in Tech: Insights from Sonatype
- Axios Compromise on npm Introduces Hidden Malicious Package
- Wicked Good Development: Evolution of Supply Chain Attacks
- Cybersecurity Executive Order: Everything You Need to Know
- The Developer's Hippocratic Oath in the Age of AI | Sonatype
- Internet of Things Cybersecurity Improvement Act of 2017
- A New OpenSSL Vulnerability Is Coming - Get Ready to Patch
- AI Model Security: Open Source ML Threats | Sonatype
- Sonatype Spots 275+ Malicious npm Packages Copying Recent Attacks
- Sonatype's 2022: A Year-End Recap
- npm Registry Support for All
- Using Sonatype Nexus Repository 3: Maven Artifacts | Sonatype
- Accelerate Secure Releases With Microsoft Copilot and Sonatype Guide
- Struts One-Two Punch Knocks Out India
- DevSecOps: Hope Is Not a Strategy
- Explore Sonatype Lifecycle's Improved Jira Add-On
- DevOps At Massive Scale
- Legal at DevOps Speed
- The Future of Maven and OSGi: Enhancing Tycho for Eclipse Development
- Stop the Low-Quality Contribution Plague
- Removing Search Guard from the Central Repository | Sonatype Blog
- Cyber Mayhem: Zero-Days in Confluence and Fortinet
- New Maven Archetypes in Nexus OSS and When to Use Them
- Modern Strategies to Accelerate Dependency Management
- The Weakest Link is Your Supply Chain: Just Ask The Pentagon
- Trust at Machine Scale: Navigating AI, Security, and the Commons
- A Data-Driven Look at Open Source Risk Management | Sonatype
- Apache Kafka Typosquats Expose Data Theft Tactics
- Sonatype Nexus Repository Performance, Compatibility and Browsing
- SBOM Software Acquisition & Secure Procurement | Sonatype
- Maven Central: Embracing Sigstore for Better Security
- Best Practices for Migrating from Apache Ant to Maven
- Quality Data Is Critical for Software Composition Analysis
- The bottom line in the Maven-Ant debate
- npm Software Supply Chain Attack Highlights New Risks
- npm Packages @rspack/core and vant Compromised by Attack
- Lazarus Group's Latest: Brandjacking Campaign on npm
- PyPI Malware Attack Targeting Python Developers | Sonatype
- Best Practices in Dependency Management: Cooking Code
- Sonatype Statement: Struts2 and Equifax Breach
- Malicious npm Packages Mimic 'Colors' Library | Sonatype
- Enhance Security with Continuous Authorization in DevSecOp
- Sonatype Lifecycle XC is now available | Sonatype blog
- Explore OpenSSL Vulnerabilities CVE-2022-3786 & CVE-2022-3602
- Benefits of Repository Managers: Continuous Build Deployment
- State of the Software Supply Chain: Dependency Management
- Security Processes at the Apache Software Foundation
- Mastering Repository Health Check 2.0 in Nexus Repository
- All Day DevOps: Practitioner-to-Practitioner
- Optimize SBOM Sharing: Best Practices for Compliance
- CVE-2017-8046: Remote Code Execution in Pivotal Spring
- Minimize Namespace Confusion and Risk with Nexus Repository
- 21 SaltStack Breaches in May and 2,900 Still Exposed
- Community Updates: Nancy Has a New Ship and Found oysteRs
- No-Fix Mediums? No High Priorities Doesn't Mean Low Danger
- Exploring Nexus, Maven 3, and Automated Testing Insights
- Designing Effective Teams for Modern Software Systems
- Achieving CI/CD With Kubernetes
- Wicked Good Development: The Impact of Vulnerability Drills
- Meet Frank Tingle: Values Champion
- New Threats to Open Source: The Event-Stream Hack Unveiled
- Sonatype Nexus Repository Supports Your Gradle Builds
- Banking on built-in security checks | Sonatype Blog
- DevOps and Opportunities in Software Supply Chain Governance
- Wicked Good Development: Overview of Devnexus Conversations
- Open Publishing, Commercial Scale
- New Critical Log4j 1.x CVEs and Chainsaw Vulnerability
- Sonatype Nexus Repository 1.3.2: New Features and Enhancements
- Open Source Malware Index: Surge in High-Severity Attacks
- Mythos Found 10,000 Vulnerabilities. The Bigger Challenge Is Fixing Them
- Nexus Delivers Repository Health Check and Git LFS Support
- Make Nexus Part of the DevOps Dozen
- Maven Central Grows Up - See the History | Sonatype Blog
- The Cost to DevOps: 27 Mufflers
- The Time Is Now to Prepare for CRA Enforcement
- GDPR One Year On: Increasing Demand for "Security By Design"
- 5 Technologies You Need for Life Cycle Container Security
- The Atlassian Story With Guest Tim Pettersen
- Merge Parent and Child POM Settings in Maven Plugin Config
- Personally, I have always been a fan of bribery | Sonatype blog
- How MOSA Principles Are Transforming DoD Cybersecurity and RMF
- Thoughts on Modern Software Supply Chain Security | Sonatype
- Struts2 Breach at Equifax Was 100% Preventable. Here's How
- Software Security Has to Start at Assembly
- What is Central? | Sonatype Blog
- Prioritizing and Automating for Optimal Developer Velocity
- NSA and Open Source: Another Controversy Brewing?
- New Report Highlights Surge in Application Vulnerabilities
- What's New With Java? A Discussion With the London Java Community
- Sonatype Nexus Repository Containers With Persistent Storage
- Introducing Our 8th Annual State of the Software Supply Chain
- Is Code Snippet Scanning Still Necessary in Development?
- Docker: The New Ordinary
- Rust in Enterprise: Best Practices and Security Insights
- Building Microservice Architecture on Kubernetes
- OSS Compliance: Lead the Way or Follow the Rules
- Automation to Cut Security Backlogs and Keep Builds Stable
- The Software Supply Chain Piques Interest
- NIS2 Compliance: Vulnerability Handling Requirements
- Please try Maven 3.0 RC1 | Sonatype Blog
- Better Software Development: Insights From the SBOM Scorecard
- Part 2, the Internet of Everything: Code, Cars, and More
- Celebrating Sonatypers
- Meet an Open Source Contributor: Chris Wininger
- Nexus and RunDeck: Tools for DevOps | Sonatype Blog
- Java.net Maven Repository Rescue Mission
- Optimizing Component Usage with Your Repository Manager
- Tracing the SolarWinds Exploit Upstream | Sonatype Blog
- 5 Quick Wins for Securing Continuous Delivery
- Learnings From 200 Billion JavaScript Downloads | Sonatype
- Yes, Policies Can Actually Speed Development
- Wicked Good Development: The Future of Maven Central
- The Future of Developer Velocity with Sonatype and AWS | Sonatype
- Unveiling Sonatype's New Logo and Tagline: A Transformation
- Exploring the Sonatype Platform for Software Supply Chains
- OWASP Top 10: Key Vulnerabilities and How to Prevent Them
- Concerned About Container Security? Try the Sonatype Platform
- Exploring HeartBleed and Hacking Through Minecraft Lessons
- Why Software Composition Analysis (SCA) Demands Precision
- OWASP LLM Top 10: Securing AI and Software Supply Chain
- Improving Maven Builds While Leaving Existing Builds Intact
- Outnumbered, Again
- Enhance Software Security with SBOMs and Gartner Insights
- Integrate Nexus IQ & OSS Index with Visual Studio Code
- npm Stops $13M Crypto Theft from Malicious Code Injection
- How Toyota’s Principles Drive Today’s Software Supply Chain
- Hudson, meet JavaServiceWrapper | Sonatype Blog
- Mythos and the AI Vulnerability Storm: Explore the Control Point
- Secure Coding Practices Learned From 36,000 OSS Projects
- Fileless Linux Malware Found in PyPI Package 'secretslib' | Sonatype
- Transforming Software Development with Sonatype Intelligence
- Major Government Attack Highlights How Log4j Is Still Unresolved
- How to Make an Executable JAR in Maven | Sonatype Blog
- New Threats: Cryptominers Flood npm & Inject Malicious PyPI
- Upgrade Sonatype Nexus Repository to Java 8 | Sonatype
- New Tools for Managing Open Source Dependencies and Risk
- Nexus Now Supports OpenSearch Standard | Sonatype Blog
- Select the Best Tools and Deconstruct the CI/CD Pipeline
- Explore CanisterSprawl: A Self-Propagating npm Malware Campaign
- AI Code Governance: Policy & Security | Sonatype
- Bringing Java and Linux Together for Continuous Deployment
- Sonatype Firewall: Quality at Velocity
- Testing Sonatype Nexus With Selenium: A Lesson in UI Testing
- Avoid lawyers, track your licenses | Sonatype Blog
- What is DevOps? Understanding DevOps Principles and Practices
- Protecting Authorizations: A Crucial Aspect of DevSecOps
- AppSec / DevOps Survey: 63% Concerned With Open Source
- Scaling Sonatype: Perspective From #SaaStr 2018
- Signal Over Noise: Reachability Analysis Is the Reality Check SCA Has Been Missing
- Fedora Blocks CC0: Navigate Open Source Licensing Challenges
- Going Beyond Manual Remediation with Repository Health Check
- Linux Malware Found in PyPI Package 'secretslib' Mine Monero
- Enhance Open Source Security with Advanced Malware Detection
- EU CRA: Implications for Software Security and Open Source
- Sonatype Launches Customer-Focused Program, Sonatype Innovate
- Counterfeit Lodash Exploits AnyDesk Targeting Windows Users
- Streamline Security with Sonatype DepShield | Guide
- Why the Cloud is Embracing BSD-Style Licenses Over GPL
- Publishing Maven Sites to Nexus Repository | Sonatype
- Beyond npm Audit to Traverse a Complex Dependency Tree
- DevSecOps is Suddenly Strategic for Everyone in Software
- Auto-Remediation Now in Eclipse, IntelliJ, and Visual Studio
- Exploring Sonatype Nexus Repository 1.0.0-beta-3.1 Release
- News and Notes from the Makers of Nexus | Sonatype Blog | Eddie Knight
- 3 DevSecOps Lessons From Conversations With 45 CISOs | Sonatype
- Ledger Connect-Kit Compromise: A Crypto Drainer Attack
- The Top 5 Trends Every DevOps Leader Needs to Know for 2024
- Writing a book with Maven: Part 1 | Sonatype Blog
- Welcome Back to Sonatype Intelligence Insights
- World Bank Group's DevSecOps Cloud Transformation Journey
- Sonatype Named a Leader in Forrester Wave for SCA | Sonatype
- Medical Device Security: A New Look at Open Source Software
- Azure Blob Storage Support Now in Sonatype Nexus Repository
- News and Notes from the Makers of Nexus | Sonatype Blog | Sylvia Fronczak
- FTC Warning in Wake of Log4j: Secure Your Software Supply Chain
- The True Cost of Not Having a Cloud Repository | Sonatype
- DevOps: Escape the Blame Game | Sonatype Blog
- Open Source Security Baseline: New Era with OSPS | Sonatype
- Survey Insights: Developers Demand Better Integration
- Simplify Maven Projects: Match Directories to Artifact IDs
- SBOM: The Idea of Transparency Turns Into Reality of Code
- Apache Struts Vulnerability: Live Updates | Sonatype Blog
- Walking in the Open Source Component Garden
- Malware Discovered in Hijacked npm Packages via Solana
- DevOps and Continuous Delivery Reference Architectures
- Steps to responsible disclosure panel discussion | Sonatype
- Proactive Security Management with Sonatype Insights
- How Developer Morale Impacts Your Software Supply Chain
- Gartner: Mitigate Risk By Hardening the Software Supply Chain
- What NIST's Definition of Critical Software Means? | Sonatype
- Are Vulnerabilities Polluting Your Software Supply Chain?
- Establishing an Open Source Governance Program | Sonatype
- New Plugin Console and Artifact Metadata in Nexus Repository
- Wicked Good Development: Testcontainers with Oleg Šelajev
- Component Management with Apache Maven Infrastructure
- Microsoft Installed an OSS Agent with Vulnerabilities
- Four Open Source Components You Need to Update Right Now
- Tripwires: When We Might Learn and Where We Don't
- Apache Maven 3.0-beta-1 Release to Enhance Development
- Maven Indexer: Explore Sonatype's Donation to Repository Search
- What to Look for in a Software Composition Analysis Solution
- DevOps at Scale & Enterprise Tool Onboarding | Sonatype
- How to Enhances R with Open Source Contributions
- Crypto Stealer Malware: Fake npm Utilities | Sonatype
- SolarWinds Software Supply Chain Attack | Protect Your Apps
- Improve Your Karma With DevOps Culture in a Box
- Enhance Maven Workflows: Index Repositories with m2eclipse
- Sonatype SBOM Generation: Leading the Way in Security
- Sonatype Can Help You Navigate DORA Compliance
- From Plexus to Guice: The Bridge and Custom Bean Injection
- Effortlessly Migrate from Ant to Maven: A Step-by-Step Guide
- Nexus 3: New Milestone Release | Sonatype Blog
- Scala Artifacts Now on Maven Central | Sonatype Blog
- CryptoJS Library Conceals Dangerous Crypto-Stealing Malware
- December 2009 News: Maven, Liferay SDK, and Java Insights
- Explore Sonatype Lifecycle and ServiceNow AVR Integration
- Differentiating Software Vulnerabilities and Malware
- Evaluating Security Measures in Open Source Projects
- DevSecOps Leaders: The Conversation Continues Online
- Microsoft Acquires npm: A Move for Public Infrastructure
- Deploying Jenkins Clusters on AWS | Automated CI/CD Platform
- Securing Repositories: Role of Checksums and PGP Signatures
- Atomic Arch npm Campaign Adds Malicious Dependency
- Bash 2014 - This Is Not a Party
- From DevOps to DevSecOps: Integrating Security into SDLC
- Important: Apache Struts framework security alert | Sonatype Blog
- Simplifying Deployment with a Repository Manager
- Why Secure Procurement Is a Must for Your Organization
- Equifax and Struts: The Importance of Prevention & Security
- 2017 State of the Software Supply Chain
- Sonatype at RSAC 2025
- Sonatype at RSAC 2025: Cybersecurity Conference Sessions
- Nexus Repository: PGP Verification and Improved Interface
- Holding the Industry Accountable: Steps for Effective DevSecOps
- Integrating Infrastructure as Code Into Continuous Delivery
- Addressing Maven Challenges: Insights from the JBoss Wiki
- The power of data in DevSecOps | Sonatype Blog
- Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT
- A World of Infinite Choice in Open Source Software
- How To Deploy a Private Docker Registry on Google Cloud
- Proxy .NET packages NuGet Gallery with Sonatype Nexus Repository
- Bryan Batty of Bloomberg Industry Group, a 4-Part Convo
- Shifting Security Left: The Innovation of DevSecOps
- Responding to Cybersecurity Threats in a VUCA World
- MavenBook now under Creative Commons 3.0 (BY-ND-NC)
- How to migrate from Ant to Maven: Project structure | Sonatype
- Java JEP'DY: Sometimes You Just Have to Let Your Hair Down
- Improving container security: Docker and more | Sonatype Blog
- The Trump White House Takes Aim at Cybersecurity | Sonatype Blog
- A Common Approach to OSS Policy: Making It Up As You Go
- Most application vulnerabilities are forever day vulnerabilities
- Free DevOps: Hatched in Response to COVID-19
- Banking Agency Mandates Better Software Supply Chain Hygiene
- PyTorch Dependency Confusion Attack: What You Need to Know
- Sonatype's Evolution: 10 Years of Innovation and Impact
- Maximizing Maven Release Plugin: Best Practices and Pitfalls
- Action Required: Struts2 Vulnerability CVE-2023-50164
- 9% of Developers Going Rogue and Contributing | Sonatype
- Wicked Good Development Episode 30: JUG, AKA the Java User Group
- Sonatype Intelligence Insights: CVE-2018-1109-Braces ReDoS Attack
- An open discussion on open source review boards | Sonatype blog
- News and Notes from the Makers of Nexus | Sonatype Blog | Wayne Jackson
- Nexus & GitLab CI Integration | A How-To Guide | Sonatype
- News and Notes from the Makers of Nexus | Sonatype Blog
- CRA and AI Regulation: The Next Chapter in Software Compliance
- TheNexus: A Community Project
- ReDoS Vulnerability in SheetJS Exposed: How to Protect Apps
- Software Composition Analysis (SCA) for Secure Development
- 86 Malicious npm Packages Named After Popular NodeJS Functions
- Explore the Sonatype Nexus REST API for Ruby Scripts
- Sonatype Racks Up Awards from Fast Company, Inc, and More
- Open Source Policy Management: Supporting Security at Scale
- Top 10 Reasons to Upgrade to Maven 3 | Sonatype
- Avoiding DevSecOps Failures: Choosing the Right Tools
- DevSecOps Lessons Learned: Guardrails for Speed & Security
- AI Role in Automation & Ethics: Insights from Gartner Report
- Top 5 Highlights from SBOM-a-Rama Fall 2024 by Sonatype
- How to Mitigate Top Open Source Software Security Risks
- Why Contextual Policy Is the Baseline for Agentic AI Development
- Distube-config npm Package Drops Info-Stealing Malware
- Navigating DevSecOps with Sonatype and Saltworks Security
- Micro Focus + Sonatype Partnership Enables Enhanced AppSec
- Bootstrapping an Alfresco Project With Maven Archetypes
- Yes, Understanding Gender Is a Professional Issue
- Revolutionize Your Business with GenAI-Centric Technologies
- Using a Software Bill of Materials (SBOM) Is Going Mainstream
- From SBOMs to AI BOMs: Why SPDX 3.0 Matters
- Improving the Nexus Search Experience
- Three reasons manual policies just don't work | Sonatype blog
- Are You Choosing the "Right" Component?
- Open and Closed Source Software Licenses Explained
- Profiling Maven Tests for Memory Leaks Using YourKit
- Nexus Repository and Microsoft NuGet Gallery OData changes
- Effective Routing Rules for Managing Nexus Repository Groups
- Streamline Python Builds | PyCharm and Sonatype Integration
- Zoosk Asks Users to Reset Passwords Following Mass Leak
- Lessons of Youth: A License to Use
- 2023 Software Supply Chain Predictions and Insights
- Maven Release Challenges: Insights and Solutions (Part 2)
- Understanding DORA Compliance Requirements | Sonatype Blog
- OMB's Rollback on Software Security Increases Risks
- Cryptominer Disguised: Python-Dateutils Targets OS Platforms
- Want to Understand Software Supply Chains? Ask Red Hat | Sonatype
- Nexus OSS vs Pro: Which Repository Manager to Choose?
- Ann Winblad Reflects: The Rise of Software
- How to Retrieve Maven Plugin Documentation | Sonatype
- Securosis Dives Deep Into Our 2014 Survey
- Malicious Intent: Open Source Developers, Protect Your Users
- How Nexus Helps Simplify Releases to the Central Repository
- CVE-2014-3483: SQL Injection in PostgreSQL Adapter
- Continuous Delivery: How to Transform Application Release
- New Enhanced JS Scanning and npm Automated Pull Requests
- Developers, Say Goodbye to Vulnerabilities and Squash Those Bugs
- DevSecOps in the Age of Containers
- Nexus Repository 3.9 Release: New UI and Firewall Support
- PyPI Attackers Drop Trojan and Info-Stealers in Packages
- Override Maven Plugin Dependencies: A Comprehensive Guide
- AI Trends in Application Security: The Gartner® Report
- Keeping Vulnerable Struts Versions Out of Nexus Repository
- 2018 DevSecOps Survey: Automation Races Against Breaches
- npm Library Hijacked: Supply-Chain Attack Targets Millions
- Activate Your Shield Against Open Source Invasions
- DevOps Meets the Sporting Goods Industry
- DevSecOps: Catching Fire | Sonatype Blog
- Explore India's Cybersecurity Framework for SBOM Compliance
- DevOps Lessons Learned from Southwest Airlines | Sonatype
- There's no analog to a repository manager in .NET. Until now.
- Secure Software Development Attestation Form | Sonatype
- Distributing Binaries: Why Not Use a Shared Filesystem?
- Explore Sonatype Lifecycle and GitLab Ultimate Integration
- Software Liability Gets Real (Global)
- Docker: Handling Circular Dependency Between Containers
- Python Packages Peek in Telegram, Set Up Windows RDP Access
- Continuous Delivery and Sonatype
- Tech Spec: Building Your App with SOUP Is a Bad Idea
- Wicked Good Development Episode 23: Demystifying Tech Debt
- 2026 Cybersecurity Predictions: A New Era of Threat Intelligence
- Enhanced OSS Index: New Data for Safer, Smarter Development
- Explore CVE-2018-14721: jackson-databind RCE Vulnerability
- Remember When Hackers Ignored Java? FBI was Just Hacked
- Dependency Confusion Packages Target Amazon, Zillow & Slack
- How to Safeguard Your Software Supply Chain
- The Evolution of OSS Index in the Age of AI | Sonatype
- Wicked Good Development: Reflect on Devnexus Conversations
- Search Sonatype Nexus Repositories Using Python and REST API
- KubeSecOps: Kubernetes Security Practices You Should Follow
- The Complex Landscape of Open Source Supply Chain Attacks
- The Role Google Plays in How Developers Find Dependencies
- How to Implement Federal DevOps and System Modernization
- What a Year of DORA Reveals About Cyber Resilience | Sonatype
- Benefits of a Repository Manager: Part I | Sonatype Blog
- Sonatype Nexus 3 Launches Into Mesosphere DC/OS
- Bryan Batty von der Bloomberg Industry Group | Sonatype
- Guice 3.0 RC2 Now Available in Maven Central | Sonatype
- AppSec Tools Explained: SAST vs SCA vs DAST | Sonatype
- Your Outdated Repository Still Works, But It May Not Be Safe
- Sonatype - 2020-0003 | npm Malicious Package 1337qq-js
- Sonatype on Federal News Radio
- New Features and Improvements in Sonatype Nexus Repository 1.4
- How AI and Vibe Coding Changed the Rules of Software Security
- Sonatype MCP Server for Dependency Management | Sonatype
- Multi-Level Staging and Build Promotion With Nexus 1.7
- Optimizing CI/CD Pipelines with Containers for Enhanced Security
- Lessons From The Hudson Build Farm | Sonatype
- Understanding the Impact of CVSS 3.1 on Enterprise Security
- The 2018 State of the Software Supply Chain Report Is Here
- Combining Open Source Policies, Practice, & Tools | Sonatype
- Understanding Software Dependencies: A Guide for Beginners
- Dynamic Storage Enhancements: 4 Improvements to Blob Storage
- AI Is Making Software Autonomous, and Governance Must Follow
- A 'fix-crash' Info-Stealer and 500+ Malicious npm Packages
- DevOps: Making the Boring Things Stay Boring
- Sonatype Nexus Repository 1.5.0 Highlights: LDAP Integration
- AgentOps Is Here: What DevSecOps Leaders Need to Do Now
- Maturing DevOps in TD Bank
- Track the Noblox.js NPM Malware: Techniques and Prevention
- Central Maven Traffic: Investigation and Analysis | Sonatype Blog
- Five Ways to Improve Your Code Quality
- Sonatype Customers Lead Innovation with Secure Software
- Meet an Open Source Developer: Lex Vorona
- Automate Nexus Reports for Security & License Management
- Unlock the Power of Binary Repositories: A Guide for DevOps
- Secure Your Software Supply Chain on AWS: Insights from ADDO
- Testing JavaScript with Apache Maven: A Comprehensive Guide
- Navigating SBOMs and New Software Security Regulations
- Vulnerability Prioritization Is Missing the AI-Era Point
- Survey: Microservices, Containers, & Serverless Development
- DevOps Leadership Series: Software Supply Chains
- Malware Roundup: A PyPI Phishing Follow-Up Plus 120 Packages
- Maven in the Wild: A Review of the Maven by Example book
- John Deere Dependency Confusion Attempt and More | Sonatype Blog
- Advanced Nexus Diagnostics with Nexus 2.0 Describe Flag
- Speedy-ts-compiler: npm Package Exfiltrates IP Addresses
- Rugged DevOps: Less Capture the Flag, More Teamwork
- Understanding Software Artifact Repositories | Sonatype
- Writing Nexus Plugins: A Comprehensive Guide | Sonatype
- Weekly Tech Roundup: Maven, OSGi, and JavaFX Updates
- Accelerate Continuous Delivery with NuGet Package Management
- Top 10 Maven Myths Debunked: Insights and Actions
- Dependency Hijacking Attack Breaches 35 Companies in Exploit
- Can the Open Source Community Save Europe from the CRA?
- 42,000 Nexus Repository Managers, and Growing | Sonatype Blog
- Malicious Python Packages Exfiltrate AWS Keys and Secrets
- NCI Leverages Sonatype Nexus to Enhance Cancer Research
- How to Publish Java Artifacts to Sonatype Nexus Repository
- Automated Setup of Sonatype Nexus Repository
- Living Our Core Values: A Journey of Growth and Inclusion
- 9 Top DevOps Conferences for Developer's | Sonatype
- Q&A: Running Docker in Production | Sonatype Blog
- Unraveling 'csrf-magic': A Supply Chain Poisoning Case Study
- Solana-Py Typosquat: How Hackers Steal Crypto Wallet Keys
- Sonatype Lifecycle Best Practices for Backup and Restore
- News and Notes from the Makers of Nexus | Sonatype Blog | Kadi Grigg
- DevOps Metrics: Measuring What Matters
- New GitLab and Lifecycle Integration Enhances Security
- Publishing Docker Images on Sonatype Nexus Repository with Maven
- DevOps Leadership Series: Gov Does DevOps (Part 2)
- 10 Best Practices for Microservice Architectures | Sonatype
- Nexus Repository 1.3.5 Released: Key Updates and Bug Fixes
- Optimize Your SBOM Management with Sonatype's SBOM Manager
- Meet an Open Source Contributor: Hervé Boutemy
- More Malware: Malicious 'botaa3' PyPI Package Taken Down
- m2e at Eclipse: What Will This Mean for You?
- DevOps: Building Better Pipelines
- We're a Java shop, we're not going to get hacked | Sonatype Blog
- 10 Years of Open Source: Growth, Challenges, & the Future
- Open Source in Financial Services: Benefits and Risks Explained
- Real World Experiences: Blackboard
- Sonatype Nexus Repository: New Support for S3 Blob Stores
- The Benefits of Remote Work Beyond Avoiding COVID-19
- DevOps: The Last Great Hope for Application Security?
- Software Composition Analysis & SBOMs in Dev Workflows
- Sonatype: 2025 Gartner Magic Quadrant for AST | Sonatype
- Top 6 Reasons DevSecOps is Needed in the Federal Government
- DevSecOps Community Survey for 2018
- Sonatype Intelligence (CVE-2018-10237): Guava Vulnerability
- Trailblazing Women Shaping the Future of Cybersecurity
- Sonatype Named Best Place to Launch a Career
- OSS Projects Take Security Seriously: Do You? | Sonatype
- Introducing Nexus Intelligence Insights | Sonatype Blog
- Learn How to Stage in Nexus Repository Pro 3.11 | Sonatype
- Six Memorable Sessions with Government DevSecOps Leaders
- Google's GWT 2.0.4 Now on Maven Central for Easier Development
- Advancing Application Delivery
- Sonatype-2020-0196: Protect Bitcoin From Malicious RubyGems
- Global Espionage: Lazarus Group Targets OSS Ecosystems
- Configuring Maven-Jetty Plugin for OpenEJB | Sonatype
- Optimizing Retention Policies and Cleanup in Nexus Repository
- Apache Maven 3.0 has landed | Sonatype Blog
- OWASP Highlights Importance of Component Security
- Analyzing Open Source Projects: Beyond Code Commits
- New Sonatype Nexus Repository and Datree Integration
- DevOps Leadership Series 2015
- Setting Up a Secure Dockerized Sonatype Nexus Repository
- What Bintray and JCenter Users Need to Know on Maven Central
- Project Highlights for World Open Source Day: My OSS Tools
- Wait... you don't have a repository manager? | Sonatype Blog
- Sonatype Newsletter: Results From Our Development Survey
- Migrating Repositories from Artifactory to Nexus Repository
- Nexus Repository | Simplifying Docker Container Management
- Stop Malware and Protect Your Repositories with Sonatype
- The New Op Model: Why State Farm Sponsored ADDO | Sonatype
- New Spring4Shell Vulnerability: Key Steps for Mitigation
- Sonatype Opens New Engineering Hub in India | Sonatype
- Defending AI Against Data and Model Poisoning Strategies
- Partitioning Nexus Repository with Privileges and Roles
- Securing the Software Supply Chain with Expert Insights
- Navigating the Rust Ecosystem & Adoption Challenges
- FINOS AI Security: Fintech AI Collaboration | Sonatype
- Automated Container Security with Red Hat Clair Integration
- Software Supply Chain Security Case Studies | Sonatype
- Biden Executive Order Calls for Enhanced Software Security
- Introducing Our 2020 State of the Software Supply Chain Report
- Why Git is the Superior Choice for Maven 3.x Development
- The Hugging Face Incident Changes the Vulnerability Equation
- Exploring Influential Books for Software Developers
- For St. Patrick's Day: A Compliance Strategy for Beerware
- DevSecOps: Secrets in the Cloud
- React Vulnerabilities: Risks and Mitigation | Sonatype
- Why You Need DevSecOps and Artifact Repositories | Sonatype
- Migrating yum to Nexus Repository Manager 3 | Sonatype Blog
- Security at the Speed of Development With 451 Research
- Wicked Good Development: Visualizing Software Architecture
- Explore Deployment Models: Self-Hosted, Cloud, & Air-Gapped
- Rebrand the Header in Nexus - The Nexus Two-Minute Challenge
- Brian Fox: What Does Sonatype Do? What Do I Do All Day?
- Q2 Open Source Malware Index 2025: Data Exfiltration Threats
- How to publish artifacts to Sonatype Nexus Repository from Gradle
- Exposing 4 Critical Vulnerabilities in Python Picklescan
- Maximizing the Value of Your SBOM: Best Practices and Tools
- Automation Overwhelms OSS Ecosystems: Q4 2025 Malware Index
- Protestware and Apache Struts RCE: Emerging Threats in OSS
- The Spectrum of AI Transparency: Beyond Open vs. Closed
- React2Shell: RCE Vulnerabilities Require Immediate Attention
- Troubleshooting Sonatype Nexus Repository 401 Errors