Lifecycle Best Practices; Use the Browser Extension - Sonatype Lifecycle & Repository Firewall / Best Practices - Sonatype Community

Lifecycle Best Practices; Use the Browser Extension

post by jzora on Aug 1, 2023

Hi, folks!

The Customer Education team here is always looking to learn from our most successful customers. Something we know that successful Lifecycle customers are doing is using the Sonatype Platform browser extension.

The Sonatype Platform browser extension for Chrome and Edge (which recently received a major upgrade) is a free, open-source resource for Lifecycle customers. Add the extension, visit a component’s page in a public repository, (Maven, PyPI, RubyGems, etc.), and the extension will evaluate that component against Lifecycle’s policies.

What’s the value? The Chrome browser extension lets you shift left. When developers get information earlier, they make better decisions earlier – and better decisions means less risk, less frustration, fewer disruptions, and higher velocity.

The best practice here is to make the browser extension available to your developers as early as you can. Start by sending an email or message to your development teams to let them know it’s available. Follow up a week later. If they don’t have a login to the IQ Server, provide them with one!

Need more convincing? Consider the following:

The bottom line is that the platform browser extension is a huge value add that puts power into the hands of your developers, and that means less work for everyone – you included!

Are you using the extension? I’d especially like to know if you have any concerns or apprehensions about the extension. Sound off in the comments below!

Resources:

post by akshaysharmahld on Aug 5, 2023

Does this extension store any user data? Also, is the extension going to slow down the browser performance since most of the Enterprises uses VM/K8 cluster behind proxies to run services.

post by phorton on Aug 8, 2023

Hey @akshaysharmahld - thanks for the question!

The Sonatype Platform Browser Extension stores its own configuration data (the details you enter when configuring the Extension) in Google Chrome’s local storage.

From our testing, the impact on browser and browsing experience is limited due to the way the Extension is written.

Hope that helps!