resources/
251 pages · Updated July 25, 2026
Pages
- 8th Annual State of the Software Supply Chain Report
- The Expansion of Software Supply Chain Regulations
- Running Integration Testing with Maven | Sonatype Maven Cookbook
- Chapter 3: Scala and Maven | Sonatype Maven Cookbook
- Making AI Software Development Safe | Sonatype Research
- MCP Servers Explained: Enhance AI Contextual Insights | Sonatype
- What Are Open Source Vulnerabilities | Sonatype
- How Lazarus Group Uses Open Source to Attack Developers | Webinar
- Maven Cookbook Foreword | Sonatype Guide
- Maven Cookbook Appendix | Sonatype
- Optimize Maven POM: Refactor & Manage | Sonatype
- Explore NIST SP 800-218 and CISA Attestation Requirements
- 2026-Q1: Webinar - Evolution of Open Source Malware
- SEBI Cyber Resilience Framework Compliance Guide | Sonatype
- Securing the Software Supply Chain in Air-Gapped Environments
- Securing Supply Chains in Federal Environments with Sonatype SAGE
- AI/LLM in the Financial Services Industry | Sonatype Webinar
- Rust Rising: Exploring the Ecosystem | Sonatype Webinar
- 101 Articles | Empowering Software Supply Chain Management
- How Al Tools are Changing the Game | Sonatype Webinar
- What is Application Lifecycle Management (ALM)? | Sonatype
- Decoding SWFT: How It Redefines Secure Acquisition | Sonatype
- Project Quality Metrics 2022 Analysis
- Chapter 5: Ruby and Maven | Sonatype Maven Cookbook
- What is DevOps and What Isn't | Sonatype
- Sonatype Recognized in the Gartner Magic Quadrant for SSSC
- Defend Your SDLC From Open Source Malware | Sonatype Whitepaper
- Automatiza La Seguridad y Enfócate En Desarrollar
- Securing Federal Applications at DevOps Speed | Sonatype
- Software Compliance Checklist | Sonatype Guide
- Open Source Malware: Defend Your Software Supply Chains | Sonatype
- Ground AI Coding Assistants for Secure Software Development
- What is Software Application Security Testing (SAST)? | Sonatype
- The State of Global Software Regulation | Sonatype Webinar
- Open Source Malware vs. Vulnerabilities | Video
- Beyond Typosquatting Attacks: Naming-Variant Threats | Sonatype
- Malicious Code vs. Vulnerabilities | Sonatype Podcast
- Top 5 CMMC Gaps That Delay Certification | Sonatype
- What is an SBOM? | Sonatype Guide
- Upcoming Sonatype Events for Innovators
- AI and the Future of Open Source Security | Sonatype Webinar
- React2Shell Uncovered: What the Critical RCE Means | Sonatype Webinar
- Accelerating Dependency Management | Sonatype Webinar
- Predicting Future Requirements and Standards
- Sonatype Nexus Repository vs. JFrog Artifactory | Guide
- What is a Software Supply Chain? | Sonatype
- Malware and vulnerabilities analogies | Sonatype Guide
- Maven by Example: A Multi-Module Project | Sonatype Guide
- SBOM Best Practices for Development Teams | Sonatype Guide
- Using SBOMs to Power SCA | Sonatype Webinar
- Cyber Resilience Act: User's Guide to Compliance | Sonatype
- Accelerate Development with Sonatype APIs
- What is Shift Left? | Sonatype
- What is CVE: Importance, Structure, and Limits | Sonatype
- Secure Containers in Your Supply Chain with Docker | Sonatype Webinar
- NIS2 User's Guide to Compliance
- What is Software Supply Chain (Really)? | Sonatype Podcast
- Sonatype Repository Firewall Product Tour
- What Is Cybersecurity? | A Sonatype Guide to Protection
- Sonatype Guide MCP + Microsoft Copilot Demo | Video
- Exploring SBOM Manager's New Features | Sonatype Webinar
- What is a Source Code Repository | Sonatype
- Outpace Open Source Malware | Sonatype Webinar
- The Risks and Rewards of AI Survey Report | Sonatype
- Sonatype Lifecycle: Auto Waivers Product Tour
- Unwrapping the Struts2 Vulnerability | Sonatype Webinar
- Maven by Example: Appendix | Sonatype Guide
- Protect Your Dev Environment from Vulnerable Components
- Software Supply Chain Management | Sonatype Guide
- Developer Productivity for Engineering Leaders | Sonatype
- Best Practices for Repository Firewall | Sonatype Webinar
- Axios Compromise Explained | Sonatype Video
- The State of Rust Adoption | Sonatype Webinar
- Software Supply Chain Threat Landscape | Sonatype Webinar
- How Organizations are Preparing for the Realities of AI-Driven Development
- Chapter 6: Web Development | Sonatype Maven Cookbook
- Software Supply Chain Management: An Introduction | Sonatype
- Unboxing Guardrails for AI-Generated Code | Sonatype Webinar
- What is Network Perimeter Protection? | Sonatype
- Sonatype H2 Product Roadmap Webinar
- SBOM: Securing Your Software Supply Chain | Sonatype Webinar
- What is the Software Development Life Cycle (SDLC Stages)
- Rust in the Enterprise | Sonatype Webinar
- Securing Financial Services from Malware Threats | Sonatype
- Government Intervention in Software Supply Chain Security
- Open Source Risks: Security & Supply Chain Guide | Sonatype
- Building a Mythos-Ready Software Supply Chain
- What Is Mythos and How Much Risk Does It Create? | Sonatype
- Software Supply Chain Management: What is SSC? | Sonatype
- Solventum’s Journey to Standardizing the Software Supply Chain
- Maven by Example: Introducing Apache Maven | Sonatype Guide
- The Effects of AI on Developers | Sonatype Whitepaper
- The 2021 State of the Software Supply Chain Report
- Chapter 7: Unit Testing with Maven | Sonatype Maven Cookbook
- Explore DORA Compliance Lessons Learned | Sonatype Webinar
- The Secure Repository Blueprint for Pipeline Security | Sonatype
- Secure the Federal Software Supply Chain in 2026
- The Time Saved by Blocking Malicious Components | Sonatype
- Exploring SBOM VEX Annotations | Video
- Insights from 9th State of the Software Supply Chain Report | Sonatype
- Maven by Example: A Simple Web Application | Sonatype Guide
- What is Post-Quantum Cryptography (PQC)? | Sonatype
- Software Security & Regulations for Medical Devices | Video
- Supply Chain Levels for Software Artifacts (SLSA) | Sonatype
- Communicating Software Compliance to the C-Suite: A Framework
- Multi Module Maven Project: Enterprise Example | Sonatype
- Exploring The Power of SBOMs: Regulations Looming | Sonatype
- CMMC Software Supply Chain Readiness Assessment
- Mitigating the Business Impact of Malware Attacks | Sonatype
- Modern SCA Best Practices for Faster Risk Reduction | Sonatype
- AI Risks in Finance | Sonatype Webinar
- Sonatype AI/ML Governance Product Tour
- Chapter 10: Repository Management | Sonatype Maven Cookbook
- How SBOMs Drive a Stronger SCA Strategy | Sonatype Webinar
- What are the Key Changes in Software Liability | Sonatype Article
- Guide to Vulnerability Management | Sonatype 101 Article
- Australian ISM Software Development Guidelines | Sonatype
- Risk Management Framework (RMF) Compliance | Sonatype Platform
- Building Trust at the Speed of AI
- Log4j Updates and Vulnerability Resources | Sonatype
- Unpickling Pytorch: Keeping Malicious AI Out | Sonatype
- Unlocking Cyber Readiness with SBOMs | Sonatype Webinar
- Sonatype SBOM Manager Product Tour
- Secure Your Software Supply Chain: A C-Suite Imperative
- Securing Air-Gapped Software Supply Chains | Sonatype Webinar
- Insights Inside Recent npm Malware Attacks | Sonatype Webinar
- Best Practices for Safe and Compliant Open Source Use | Sonatype
- Chapter 4: Ant and Maven | Sonatype Maven Cookbook
- The Power of Binary Repositories | Sonatype DevOps Webinar
- Assessing your Open Source Security Efficacy | Sonatype Webinar
- Stop Malicious Packages Before They Hit Your Build
- SBOM in DevSecOps: Best Practices | Sonatype
- NIS2 Compliance Guide | Optimize Your Software Supply Chain
- Best Practices for CISOs & AppSec Leaders | Sonatype Webinar
- Modern Vulnerability Management | Sonatype Fireside Chat
- Navigating the Evolving SWFT Initiative | Sonatype Webinar
- Creating Mission Ready SBOMs | Sonatype Webinar
- Preparing for CRA Enforcements | Sonatype Webinar
- Chapter 1: Cooking with Maven and OSGi | Sonatype Maven Cookbook
- Precision Malware: How AI Transformed Open-Source Threats
- Sonatype Advanced Legal Pack Product Tour
- About the 2022 Software Supply Chain Report
- SBOM Manager: Everything You Need to Know | Sonatype Video
- Releasing Software with Maven | Sonatype Maven Cookbook
- SBOM 101: Evolving Regulations in Software Development
- Software Composition Analysis (SCA) Best Practices | Webinar
- Supercharge AI DevSecOps by Fixing Your Flow Problems First
- Software Supply Chain Management: A Shifting Industry
- The False Sense of Security | Sonatype Webinar
- The CVE Wake-Up Call | Sonatype Webinar
- What Is Software Composition Analysis (SCA Security)
- The Future of Dependency Management | Sonatype Webinar
- What is Open Source Malware? Protection Guide | Sonatype
- Sonatype Guide Overview | Video
- Why Should Your Organization Choose Nexus Repository Pro
- Software Supply Chain Management: App Development | Sonatype
- Unveiling Vulnerabilities: Identify & Score Risks | Sonatype
- 10 Frequently Asked SBOM Questions Answered | Sonatype Guide
- Maven by Example: Preface | Sonatype Guide
- SBOM 101: What is an SBOM? | Sonatype Video
- The 2024 Forrester Wave™ Software Composition Analysis
- DORA Compliance Checklist | Sonatype Guide
- Building Trust in AI-Driven Software Development | Sonatype Guide
- Prácticas de SCA para reducir riesgos de forma más rápida e inteligente
- Comparing Open Claw vs. Spring Projects | Sonatype Video
- Inside npm Malware Attacks: Protecting Your Software Supply Chain
- Policy Engine Explained | Secure Open Source with Sonatype
- Sonatype Recognized in the Gartner Magic Quadrant for SSSC
- Best Practices for Nexus Repository | Sonatype Whitepaper
- Maven Cookbook | Sonatype Guide
- Software Development in the Age of AI | Sonatype Webinar
- What is Software Security? | Sonatype
- What is Application Security? | Types, Testing, and Risks
- Development Automation You Can Count On | Sonatype Webinar
- SBOM Regulatory Framework Overview | Sonatype Video
- Why Responsible Open Source Use Matters | Sonatype Webinar
- Early Detection, Early Prevention | Sonatype Guide
- What is a Software Bill of Materials | Sonatype
- AI-First Software Delivery Readiness Checklist | Sonatype
- Sonatype Lifecycle: Assisted Remediation Product Tour
- Software Supply Chain Maturity
- How Lazarus Group is Weaponizing Open Source | Sonatype
- One Year of the DORA Regulation | Sonatype Webinar
- CRA and AI Regulation: What's Next for Software Compliance?
- How to SafeGuard Your Software Supply Chain | Sonatype Webinar
- Secure Claude Projects with Sonatype Guide | Video
- Diving Into Open Source Dependencies | Sonatype Podcast
- How DevOps Pioneers are Leading Organizational Change | Sonatype
- SBOM SOS: 6 Things to Do Right Now | Sonatype Guide
- Software Supply Chain Management: Understanding the Basics
- EMEA SBOM Regulatory Requirements | Video
- Diving into Software Supply Chain Security | Sonatype Webinar
- The 2 Billion Hack: npm Compromised Packages | Sonatype Video
- DORA User's Guide to Compliance | Sonatype
- CI/CD Pipeline Security Explained | Sonatype
- New Zealand Information Security Manual (NZISM) Guide | Sonatype
- Navigating Software Regulations, SBOMs and Beyond | Sonatype
- Best Practices for SCA Tools and Programs | Sonatype Guide
- DevSecOps Automation in Financial Services | Sonatype Webinar
- Software Supply Chain Resources, Guides & Tools | Sonatype
- Software Compliance Checklist for Global Regulations
- Software Bill of Materials Explained | Sonatype Video
- Federal Strategies for Compliant AI Adoption | Sonatype Webinar
- 2024 Open Source Malware Threat Report | Sonatype
- Download the SANS 2023 DevSecOps Survey Report | Sonatype
- Implement CERT-in Software Development Guidelines | Sonatype
- Maven by Example: Installing Maven | Sonatype Guide
- Integrating Open Source Supply Chain Management into DevOps
- Open Source Software: What is OSS? | Sonatype
- Maven by Example | Sonatype Guide
- How AI is Reshaping Open Source | Sonatype Webinar
- What are Large Language Models (LLMs)? | Sonatype
- Docker Security Best Practices for Containers | Sonatype
- Maven by Example: A Simple Maven Project | Sonatype Guide
- The CVE Crisis: Why Vulnerability Data Is Broken
- Dependency Tracking vs Scanning: Key Differences | Sonatype
- Embrace Modern Software Development in the AI Era | Sonatype
- Our Top 5 Vulnerable Open Source Components | Sonatype Whitepaper
- AI Regulation Compliance in Software Development | Sonatype
- Sonatype SBOM Manager: Bom Visualizer Demo | Video
- Regulations and Compliance Deep Dive | Sonatype Webinar
- Mythos-Ready: Build Security for the AI Vulnerability Storm
- Sonatype Nexus Repository Product Tour
- Join Our Exclusive Webinar: Shai-Hulud & the Nx Campaign
- What is DevSecOps? | Integrating Security Into The SDLC
- AppSec Best Practices for the AI Era
- Sonatype Guide and AWS Kiro | Demo Video
- Complete Guide to AIBOMs | Sonatype
- How to Achieve PCI Compliance | Sonatype Guide
- DevSecOps Reference Architecture Download | Sonatype
- Autonomous Development Meets Real-World Risk | Sonatype Webinar
- The Ultimate SBOM Guide | Sonatype
- Software Composition Analysis Best Practices | Sonatype Webinar
- Preparing SBOMs for Audits | Sonatype Guide
- Sonatype CEO on the Future of AI-Native Software Development
- Open Source Supply, Demand, and Security
- Exploring Open Source Compliance in Fintech | Sonatype Video
- Chapter 2: Groovy Maven | Sonatype Maven Cookbook
- The 2026 CISO & CTO AI Governance Playbook Framework | Sonatype
- What is Dynamic Application Security Testing (DAST)? | Sonatype
- Open Source Dependency Management: Trends and Recommendations
- What is a Software Dependency? | Sonatype
- Software Supply Chain Management: Conclusion | Sonatype Guide
- Attacking the Assembly Line | Sonatype Research
- Developer Velocity with Sonatype and AWS | Sonatype Webinar
- The AI Vulnerability Storm | Sonatype
- A Timeline of SSC Attacks, Curated by Sonatype
- U.S. SBOM Regulatory Requirements | Sonatype Video
- CRA Compliance Checklist | Sonatype Guide
- Dependency Management in Financial Services | Sonatype Webinar
- Simplify Dependency Management with Sonatype Developer