# Sonatype Lifecycle XC Is Now Available

**September 14, 2017**  
By [Michelle Dufty](/content/blog/author/michelle-dufty/index.html)

2 minute read time

I am pleased to announce that we recently released [Sonatype Lifecycle](/content/products/open-source-security-dependency-management/index.html) XC which includes expanded coverage for a larger ecosystem of languages including Ruby, PHP, Swift, Cocoapods, and others.

As we promised earlier this summer with the announcement of XC, Sonatype now provides a win-win intelligence engine that combines the depth of Sonatype Lifecycle data for machine automated open source controls with the breadth of Sonatype Lifecycle XC data for foundational open source governance. And with the recent news about [Equifax](/content/customer-stories/equifax-success-in-security-transformation/index.html) and the [Struts2 vulnerability](/content/blog/2017-struts2-vulnerability-exploit-speed-matters/index.html), we all know how important it is to have visibility into a [software bill of materials (SBOM)](/content/resources/articles/what-is-software-bill-of-materials/index.html) and automatically govern the use of open source components within the [software supply chain](/content/resources/articles/what-is-software-supply-chain/index.html).

To learn more about Sonatype Lifecycle XC, watch this [video](https://vimeo.com/233683634) from Product Owner Jamie Whitehouse or visit our [website](/content/products/integrations/index.html) to learn more.

Also, download the new [whitepaper](/content/resources/index.html) to learn why Gartner believes it is critical for organizations to create a trusted software supply chain, and why tools like Sonatype Lifecycle and Lifecycle XC are critical to create a trust but verify approach with your open source suppliers.

Written by **Michelle Dufty**  
Michelle Dufty is the Senior Director of Product Marketing at Sonatype where she brings solutions to market that unite development, security, and operations teams to accelerate software innovation while minimizing open source risk.

Tags:  
nexus exchange Product Sonatype Lifecycle
