<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1127487224079104&amp;ev=PageView&amp;noscript=1 https://www.facebook.com/tr?id=1127487224079104&amp;ev=PageView&amp;noscript=1 ">

Les enseignements de l'analyse de 36 000 projets d'OSS | Communiqué de presse


Communiqués

Dernier scoop sur Sonatype

 

Micro Focus renforce son partenariat stratégique avec Sonatype et apporte la meilleure sécurité Open Source du marché à tous les clients Fortify

New Joint Solution Delivers a Single, Fully Integrated Application Security Platform for Managing Open Source Risk and Vulnerabilities for Fortify on Demand and Fortify On-Premise

SANTA CLARA, CA -- Sept. 9, 2019 – Micro Focus (LSE: MCRO; NYSE: MFGP) today announced an expanded strategic partnership with Sonatype to provide the combined power of Micro Focus' application security as a service, Fortify, and Sonatype's leading automated open source governance solution, to even more customers. The new relationship, which promotes Sonatype as Fortify's preferred Software Composition Analysis (SCA) partner, delivers the advantages of a single, fully integrated application security platform, without compromising depth and capability in managing open source risk and vulnerabilities.

Sonatype va plus loin avec Go, en fournissant une solution de sécurité entièrement automatisée à un langage de programmation en plein essor

The Nexus Platform now enables Go development teams to automatically control open source risk across the entire software development lifecycle

SAN DIEGO – GopherCon - July 24, 2019 -- Today, Sonatype, the inventors of software supply chain automation, announced full support for Go (Golang) across the Nexus Platform, giving Go development teams an easy way to manage Go packages and automatically eliminate security risk across the entire software development lifecycle, including production applications.  With the addition of Go, the Nexus Platform now supports 42 programming languages and package formats, further meeting the diverse needs of enterprise development teams. 

Le rapport sur l'état de la chaîne logistique logicielle en 2019 révèle les bonnes pratiques de 36 000 équipes de développement de logiciels open source

An additional study of 12,000 commercial software engineering teams identified key characteristics of exemplary secure coding practices

LONDON – DevOps Enterprise Summit - June 25, 2019 -- Sonatype today released its fifth annual State of the Software Supply Chain Report. This year’s report reveals the best practices exhibited by exemplary open source software projects and commercial application development teams. As in years past, it also examines the rapidly expanding supply and continued exponential growth in consumption of open source components.

La conférence dédiée aux utilisateurs Nexus de Sonatype, qui réunit 2 000 leaders DevSecOps, sera diffusée gratuitement en direct

The June 12 Conference Features 44 Nexus Innovators, Customers and Industry Leaders

Fulton, MD – June 10, 2019 -- Sonatype, the inventors of software supply chain automation, will host its second annual Nexus User Conference on June 12, 2019. The free, live, and online event will bring together more than 2,000 DevOps and DevSecOps practitioners to galvanize the industry and share actionable insights, technical how-to’s, and first-hand stories about DevSecOps transformations.

Sonatype propose de nouvelles fonctionnalités pour Red Hat Quay, offrant aux utilisateurs la sécurisation continue de leurs conteneurs open source

BOSTON - Red Hat Summit – May 7, 2019 - Sonatype, the inventors of software supply chain automation, announced new capabilities for Red Hat Quay enterprise container registry enabling modern organizations to automate and enforce open source governance policies in the containerized applications they use every day.

Sonatype Named to Best Workplace Lists by Both Washingtonian Magazine and Battery Ventures

Company CEO also Chosen as a Tech10 Honoree by Baltimore Business Journal

Fulton, Md.  – April 29, 2019 –  Sonatype, the inventors of software supply chain management, is proud to announce its been named one of the 50 Highest Rated Private Cloud Computing Companies on Glassdoor by Battery Ventures and one of Washingtonian Magazine's 50 Great Places to Work.

Sonatype et HackerOne s'associent pour accroître la sécurité open source

Pioneering program makes reporting open source vulnerabilities easier than ever

Fulton, Md.  – March 21, 2019 Sonatype, the inventors of software supply chain management, today announced a partnership with HackerOne, the leading hacker-powered security platform, to create The Central Security Project (CSP). The first-of-its-kind program brings together the ethical hacker and open source communities to streamline the process for reporting and resolving vulnerabilities discovered in libraries housed in The Central Repository, the world’s largest collection of open source components.

5 518 professionnels de l'informatique révèlent les meilleures pratiques de l'élite DevSecOps

2019 DevSecOps Community Survey shows mature programs are 700% more likely to automate security, as adversaries accelerate pace

SAN FRANCISCO - RSA Conference – March 4, 2019 Sonatype, the inventors of software supply chain automation, today published findings from its 6th annual DevSecOps Community Survey of 5,558 IT professionals, making it the largest DevSecOps survey ever conducted. The survey, developed in partnership with CloudBees, Carnegie Mellon’s Software Engineering Institute, Signal Sciences, 9th Bit, and Twistlock, unveiled a new portrait of what organizations with elite DevSecOps programs look like in the face of accelerating attacks from bad actors.

Nexus Firewall de Sonatype protège désormais JFrog Artifactory

World’s First Application Security Solution that Universally Protects DevOps Pipelines from Vulnerable Open Source Components

Fulton, MD.  – February 28, 2019 –  Sonatype, the inventors of software supply chain management, announced today that Nexus Firewall is now available to JFrog customers to automatically stop vulnerable open source components from entering into Artifactory Repository Managers.  

Kenna Security et Sonatype s'associent pour améliorer la gestion des vulnérabilités basée sur les risques grâce aux informations open source

New relationship underscores the need for enterprises to manage open source risk as part of an integrated and comprehensive security program

SAN FRANCISCO, Calif. and FULTON, Md. – February 26, 2019 – Today, Sonatype, the leader in automated open source governance and Kenna Security, a leader in predictive cyber risk, announced a strategic partnership to enhance the risk-based vulnerability management strategies of modern enterprises with best-in-class intelligence on open source components.