Keep Software Dependencies Secure with Sonatype Lifecycle

Keeping Software Dependencies in Check With Sonatype Lifecycle

March 18, 2019
By Nikita Belokopytov

5 minute read time

In this article, I explain the risks of software dependencies and how to mitigate them with appropriate tools.

Damned If You Don't

Whether you're a developer, CTO or tech lead, I bet you've faced the dilemma of whether to add a software dependency to your software.

While they have incredible benefits, they do come with some obvious trade-offs along the following lines:

Detecting a problem of the third category is trivial, but how do you detect issues belonging to the first two? If your company is small and there are only a few dependencies here and there  —  you can do a manual check. However, when you start to scale your business and the number of engineers starts going into tens and hundreds, you have to scale your approaches, processes and tools.

Enter Sonatype Lifecycle (IQ Server)

You might have heard of Sonatype Nexus Repository  —  it's a place where you can upload your binary and share it with other people within your organization or outside of it. With tools like Gradle or Maven, anyone with access can depend on your code with little effort. Here's a great article if you'd like to know more about it and its differences from jcenter and Maven Central.

When you publish anything on Sonatype Nexus Repository, you can inspect your code for known vulnerabilities or license breaches by flipping a switch in the settings. However, should you decide against publishing, you can still use their Sonatype Lifecycle  —  a powerful engine that allows you to create your own company policies on dependencies usage, and a scanner tool that generates reports about your code's compliance to them. After being generated, these can be found in a dashboard with detailed descriptions of all the vulnerabilities found, the respective common workarounds and best practices of usage.

Refresher Course

After briefly skimming through the official tutorial, you will find that you need the following:

java -jar <NEXUS_DIR>/nexus-iq.jar -i <APPLICATION_ID> -s <NEXUS_IQ_SERVER_URL> -a <USERNAME>:<PASSWORD> <ARTIFACT>

Presto! Now if you go to your dashboard, you will see the entry under your artifact's name, with the results of the scan. Of course, instead of a single file, you can supply the whole folder to Sonatype IQ CLI and analyze everything inside.

Everything Sonatype Lifecycle can analyze that is. It's supported formats include jar, war, ear, tar, tar.gz, zip and even Docker images. The official help says there are many more supported ones, like C-style .o files and yet there is one omission.

It's a powerful tool and something that any tech lead or CTO would appreciate, but there is a catch.

It was not built for Mobile Apps.

While it may seem like a headache to figure out how to add your Android and iOS dependencies to this dashboard, the outcome is worth it - a single source of truth for your company's code safety. In part two I will teach you some tricks that will help you integrate it with Android.

A version of this article originally appeared on Hackernoon and has been republished with permission from the author.

Written by Nikita Belokopytov

Nikita Belokopytov is a Senior Software Engineer @ Quandoo. He loves lean startup and design thinking.

Tags

devsecopsnexus IQ serverProductSonatype Lifecycle