Search

Filters

Clear filters

Products

Search results

  1. API Reference \ Use the Swagger API references to explore supported Sonatype REST APIs, review available endpoints, understand request and response formats, and identify required permissions before integrating with Sonatype products.

API Reference Landing Page

  1. Sonatype Guide \ Sonatype Guide is an AI-first product that enhances developer and application security (AppSec) productivity through automation and data intelligence. By extending Sonatype’s trusted data into modern Model Context Protocol (MCP)–aware IDEs, Guide helps developers and AI tools select the best and safest open-source components while simplifying and optimizing dependency management.

Sonatype Guide

  1. my.sonatype.com \ Your central hub for managing Sonatype accounts, cloud solutions, and organization settings.

my.sonatype.com

  1. Sonatype Repository Firewall \ Sonatype Repository Firewall is the first line of defense for controlling the open-source components allowed into your Software Development Lifecycle.

Repository Firewall

  1. Sonatype Lifecycle \ Sonatype Lifecycle is the solution to identify open-source risks and secure your software supply chain. With Lifecycle, you create custom policies that are enforceable across all stages of your software development lifecycle (SDLC).

Sonatype Lifecycle

  1. Sonatype Nexus Repository \ Sonatype Nexus RepositoryTM comes in Professional and Community Editions. See the features available for our Professional edition or the direct comparison with the community edition.

Sonatype Nexus Repository

  1. Sonatype Platform Overview \ Sonatype combines open source intelligence, malware protection, AI governance, and SBOM management for secure software development.

Sonatype Product Overview

  1. Guide API Reference \ Use the Swagger Guide API reference for searching component and vulnerability data.

Sonatype Guide / Guide API Reference

  1. Repository Firewall Pro \ Sonatype Repository Firewall Pro (https://firewall.sonatype.app) is a cloud-based service that protects your software supply chain by blocking malicious open-source packages before they reach your artifact repository.

Repository Firewall / Repository Firewall Pro

  1. Enterprise Reporting \ Enterprise Reporting is your one-stop access to understand your organization’s repository risk exposure, protection coverage, and factors affecting the overall security posture of your software supply chain. It summarizes how Sonatype Firewall impacts the security profile of repositories and artifact consumption across your organization.

Repository Firewall / Enterprise Reporting

  1. Configure Identity Provider (IdP) \ This section is only available for Sonatype Cloud.

my.sonatype.com / Configure Identity Provider

  1. Integrate Firewall with Zscaler \ Zscaler is a cloud-native cybersecurity platform to securely connect users, devices, and applications, regardless of their location. Think of it as a security checkpoint in the cloud that all your organization's traffic can pass through for inspection and protection.

Repository Firewall / zscaler

  1. Sonatype GitHub Actions \ This integration provides a set of GitHub Actions for interacting with different Sonatype products directly within your GitHub workflows.

Sonatype Integrations / Sonatype GitHub Actions

  1. The Sonatype for Azure DevOps extension integrates with the Azure DevOps pipeline to run policy evaluations in the build workspace. It adds a new step within the build, during which Sonatype IQ Server scans applications to identify any open-source security, license, or quality policy violations. It can be configured to fail the build or generate a warning. This allows the build maintainers to understand the reasons for build failures and plan a remediation strategy.

Sonatype Integrations / Sonatype for Azure DevOps

  1. Repository Firewall Release Notes \ Repository Firewall release notes are included in both the Sonatype Nexus Repository Release Notes and Sonatype IQ Server Release Notes.

Repository Firewall / Repository Firewall Release Notes

  1. Notable Integrations Changes \ This page summarizes the major changes in Sonatype integrations. Note that this is not an exhausted list of all changes across all integrations; detailed change logs are available within each individual integration's main help page. This page focuses only on highlighting major changes.

Sonatype Integrations / Notable Integrations Changes

  1. As applications grow in size and complexity, so does the potential for vulnerabilities. The attack surface also expands with increased reliance on open-source software components. Given tight deadlines and competing priorities, it is often impractical to remediate every vulnerability. A pragmatic way to approach a near-zero risk state in a limited timeframe is to target the open-source software vulnerabilities that lie along the execution paths of an application i.e. are reachable.

Sonatype Developer / Reachability Analysis

  1. Policy Compliant Component Selection \ The DevSecOps best practice for build reliability is to specify exact versions of open source dependencies in the build manifest. A common norm for some projects is to leave the dependency versions undefined or defined as a range of versions. When the latest version has violations blocked by Repository Firewall the npm client errors without a clear path forward.

Repository Firewall / Policy Compliant Component Selection

  1. Namespace Confusion Protection \ Namespace Confusion (also known as Dependency Confusion) is a Software Supply Chain Attack where malicious packages are installed using weaknesses common in dependency management practices. Repository Firewall offers protection from dependency confusion with features targeting different types of attacks.

Repository Firewall / Namespace Confusion Protection

  1. The Sonatype IQ Command Line Interface (CLI) is the multi-tool for performing a Lifecycle Analysis. Evaluations of your applications are either run manually or automatically using the CLI in many environments.

Sonatype Integrations / Sonatype IQ CLI