SON NexusFirewall infographicsFINAL.pdf
SHIFT SECURITY PRACTICES LEFT. ALL THE WAY LEFT.
WINNERS INNOVATE, LOSERS DON’T:
The best and the brightest use precise open source component intelligence early, everywhere, and at scale.
HERE’S WHY:
Open source component usage is massive and it’s growing.
7,000 new projects and 70,000 Over 100 billion download open source components requests of Java, npm, PyPI, (versions) are released every week and RubyGems in 2016.
200,000+ 80% components downloaded by an application is made up of an average company annually of open source components.
IT MUST BE MANAGED.
The best organizations manage component sourcing through repository managers. The rest employ free-for-all-methods.
THOUSAND
30,000 → 150,000 growth in the number of active instances of Nexus Repository in the last 4 years.
IT MUST BE SECURE.
How do the best organizations harness all the good and none of the bad?
1 in 16 40% 23,000
| open source component | of organizations are increasing | organizations use RHC daily to | |
|---|---|---|---|
| downloads contain a known | their level of component | measure the 58 million | |
| security vulnerability | analysis using Repository Health Check (RHC) | components living inside local | repositories |
IT MUST BE AUTOMATED.
According to Gartner:
- By 2019, more than 70% of enterprise DevOps initiatives will have incorporated automated security vulnerability and configuration scanning for open source components.
- “Implement an ‘OSS firewall’ to proactively prevent developers from downloading known vulnerable code.”
BUILD QUALITY IN FROM THE START.
Create value early in the development process by automatically blocking defective components with Nexus Firewall. Easily identify good components from bad components and block the bad ones from entering your repository through customized policies.
quarantine area Nexus Firewall
proxy repo staging repo production
LEARN MORE
- Watch the video: Block Bad Components Using Nexus Firewall
- Read the Gartner report - DevSecOps: Seamlessly Integrate Security into DevOps
- Know the research - Enable Perimeter Defense for Software Development
- Watch the presentation - A financial services organization shares their use of Nexus Firewall Copyright © 2018, Sonatype Inc. All rights reserved.