# SHIFT SECURITY PRACTICES LEFT. ALL THE WAY LEFT.

## WINNERS INNOVATE, LOSERS DON’T:

**The best and the brightest use precise open source component intelligence early, everywhere, and at scale.**

## HERE’S WHY:

##### Open source component usage is massive and it’s growing.

**7,000 new projects and 70,000 Over 100 billion download** open source components requests of Java, npm, PyPI, (versions) are released every week and RubyGems in 2016.

**200,000+ 80%** components downloaded by an application is made up of an average company annually of open source components.

## IT MUST BE MANAGED.

##### The best organizations manage component sourcing through repository managers. The rest employ free-for-all-methods.

#### THOUSAND

**30,000 → 150,000** growth in the number of active instances of **Nexus Repository** in the last 4 years.

## IT MUST BE SECURE.

##### How do the best organizations harness all the good and none of the bad?

**1 in 16 40% 23,000**

| open source component | of organizations are increasing | organizations use RHC daily to |  |
|----------------------|--------------------------------|------------------------------|--|
| downloads contain a known | their level of component | measure the 58 million |  |
| security vulnerability | analysis using Repository Health Check (RHC) | components living inside local | repositories |

## IT MUST BE AUTOMATED.

##### According to Gartner:

- By 2019, more than **70% of enterprise DevOps initiatives will have** **incorporated automated security vulnerability** and configuration scanning for open source components.
- “Implement an **‘OSS firewall’ to proactively prevent developers from** **downloading known vulnerable code.**”

## BUILD QUALITY IN FROM THE START.

Create value early in the development process **by automatically blocking** **defective components with** Nexus Firewall. **Easily identify good components from bad components and block the bad ones from entering your repository through customized policies.**

**quarantine area** **Nexus Firewall**

**proxy repo staging repo production**

### LEARN MORE

- Watch the video: **Block Bad Components Using Nexus Firewall**
- Read the Gartner report - **DevSecOps: Seamlessly Integrate Security into** <u>DevOps</u>
- Know the research - **Enable Perimeter Defense for Software Development**
- Watch the presentation - **A financial services organization shares their use** <u>of Nexus Firewall</u> **Copyright © 2018, Sonatype Inc. All rights reserved.**
