Sonatype Lifecycle Enhancements Boost Speed and Security

Sonatype Lifecycle Enhancements Boost Speed, Security, and Productivity

March 30, 2023
By Nitin Phadnis

6 minute read time

Can a mature platform be further improved to help teams in their journeys through the software development life cycle (SDLC)? The answer is yes. Sonatype Lifecycle is designed to help shift development processes left, as it continuously monitors for problems at every stage of the SDLC and ensures automated remediation to keep development moving.

Powered by Sonatype Intelligence, Sonatype Lifecycle is the bridge between developers and security teams. It perfectly balances the drive to put the pedal to the metal (developer velocity) with the need to ensure that development pipelines and production setups are secure and healthy (application security).

What's New in Sonatype Lifecycle?

As the software development landscape and security threats continue to evolve, Sonatype Lifecycle has kept pace to address new challenges and provide new features and capabilities. Sonatype's development team regularly releases updates and new versions of Sonatype Lifecycle to stay current with industry trends and customer needs. Let's take a quick look at the recent updates that will further modernize SDLC processes.

Drive Operational Excellence

Developer Productivity Gets a Boost

With the N-level hierarchy feature, we reworked our UI and application logic to ensure that data changes apply to the appropriate node in an organization's hierarchy. In simple terms, Sonatype Lifecycle can now model any organizational structure and decisions. Permissions, policy, and configuration can easily be managed across any node in that structure.

For example, organizations can decide if they want to apply a change to policy, permissions, or data across all companies, a particular organization, a group of applications, or just one specific application.

Organizations At Scale helps:

Additional features such as Notification and Action Overrides allow better and more timely decision-making.

Experience Intelligent Security

Users can now add:

Additional policy constraints have been added so that this new information can be utilized to maximize remediation efforts and ensure that teams tackle the most impactful security vulnerabilities first.

Maven Call Flow Analysis solves this problem by determining if there is any path from the code to the vulnerable method. And if there is, it quickly publishes a policy alert letting users know it needs remediation first.

In essence, Call Flow Analysis allows our customers to prioritize which vulnerabilities to remediate. This helps them target and remediate those most likely to impact their security and code quality, and effectively reduce the "attack surface."

Sonatype InnerSource Insight gives organizations a look at their own inner source (proprietary components) and helps reduce costs and vulnerability exposure. In addition to enhancing security posture, this feature significantly improves developer productivity by reducing the time required to identify where a problem lies.

New to Sonatype Lifecycle?

Sonatype is here to help. We offer plenty of documentation on getting started and best practices. If you have further questions about how Lifecycle can help organizations achieve their perfect development workflow, book a demo today. Our experts are always ready to talk.


This post was co-written with Dariush Griffin.

Written by Nitin Phadnis
Nitin Phadnis is a Senior Product Marketing Manager at Sonatype. When he's not working, Nitin loves spending time with family, reading, and watching F1 races.

Tags
secure software supply chain, Open Source, Sonatype Platform, Sonatype Lifecycle