Getting Started with Self-Hosted Repository Firewall
Getting Started with Self-Hosted Repository Firewall
Use this page to connect your Nexus Repository on-prem instance to Repository Firewall. If you use SaaS instances, see Getting Started with Repository Firewall Cloud.
Repository Firewall is a set of features, powered by IQ Server, that integrate with Nexus Repository or through a plugin with JFrog Artifactory.
Configure the Repository Firewall with the following steps:
Follow these instructions to install the IQ Server and add the Repository Firewall license. This step is not required with Sonatype Cloud tenants.
Connect your artifact repository to the IQ Server instance.
Select your repositories to be protected by the Repository Firewall.
Configure your policies to quarantine new violating components and protect against introducing risk.
Inform your development teams of the change to set expectations.
To configure Nexus Repository, review the Repository Firewall Capability
Connect to an Artifact Repository
Your Repository Firewall license supports either Nexus Repository or JFrog Artifactory.
Nexus Repository
Repository Firewall currently works with Nexus Repository Cloud, Community, and Pro editions.
To use Repository Firewall with Nexus Repository, customers must configure Nexus Repository to connect to an IQ Server instance that has a valid Repository Firewall license.
See Nexus Repository 3 Pro Setup
JFrog Artifactory
For JFrog Artifactory you are required to install and manage the Repository Firewall for Artifactory plugin to enable the functionality. Note that Artifactory SaaS is not supported.
Review the Repository Audit
Once enabled, the Repository Firewall begins to audit repositories for open-source threats and generate a report of the current risk.
Components currently in your artifact repository are not quarantined; there is no disruption to your existing builds and deployments.
Learn more about the Repository Results View.