Improved Dependency Management for Java in Nexus Lifecycle - Sonatype Lifecycle & Repository Firewall - Sonatype Community

Improved Dependency Management for Java in Nexus Lifecycle

post by ashames on Mar 27, 2020

Alyssa Shames

Summary
Managing dependencies is one of the best ways to assess the risk disposition of your organization’s applications and components. Contextual awareness around how dependencies are linked and how dependencies enter into your SDLC will improve research around these risks and potentially change development behavior over time. As such, Sonatype is happy to announce improved dependency management capabilities for Java in Nexus Lifecycle.

What’s Changing in Nexus Lifecycle
Release 88 introduced a new section in your transitive dependency’s component information panel (CIP) titled ‘Recommended Remediation.’ It shows which direct dependencies brought in that transitive and links back to the direct dependency (example below).

\915×432 66.7 KB](https://cx-discourse-user-uploads.s3.dualstack.us-east-1.amazonaws.com/original/2X/7/706f1bd55e45ae51033d9519f1e85b6464cedabe.png "")

For direct dependencies, you will still see ‘Recommended Version’ providing the next version with no policy violation (this is the current default policy).

\910×431 55.4 KB](https://cx-discourse-user-uploads.s3.dualstack.us-east-1.amazonaws.com/original/2X/1/12d74adca907a4ad6a859c0b62a2e26f3be4b9b6.png "")

Benefits
The new section and updated links are designed to help you attack remediation from the top down. By focusing on parent components first, you can tackle multiple remediations at once, ultimately aiding in prioritization and decreasing unnecessary research efforts. You may also experience:

Dependencies in Action

Where can I ask additional questions?
You can reply directly to this post. If you are not already registered to the Sonatype User Community, you will be prompted to create an account. This will allow you to create and reply to other threads initiated by both the Sonatype team and your community peers.