DevOps.com

  • Latest
    • Articles
    • Features
    • Most Read
    • News
    • News Releases
  • Topics
    • AI
    • Continuous Delivery
    • Continuous Testing
    • Cloud
    • Culture
    • DataOps
    • DevSecOps
    • Enterprise DevOps
    • Leadership Suite
    • DevOps Practice
    • ROELBOB
    • DevOps Toolbox
    • IT as Code
  • Videos/Podcasts
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • DevOps Unbound
  • Webinars
    • Upcoming
    • Calendar View
    • On-Demand Webinars
  • Library
  • Events
    • Upcoming Events
    • Calendar View
    • On-Demand Events
  • Sponsored Content
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • Security Boulevard
    • Techstrong Research
    • DevOps Chat
    • DevOps Dozen
    • DevOps TV
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
  • Media Kit
  • About
  • Sponsor
  • AI
  • Cloud
  • CI/CD
  • Continuous Testing
  • DataOps
  • DevSecOps
  • DevOps Onramp
  • Platform Engineering
  • Sustainability
  • Low-Code/No-Code
  • IT as Code
  • More
    • Application Performance Management/Monitoring
    • Culture
    • Enterprise DevOps
    • ROELBOB
Hot Topics
  • Chronosphere Adds Professional Services to Jumpstart Observability
  • Friend or Foe? ChatGPT's Impact on Open Source Software
  • VMware Streamlines IT Management via Cloud Foundation Update
  • Revolutionizing the Nine Pillars of DevOps With AI-Engineered Tools
  • No, Dev Jobs Aren’t Dead: AI Means ‘Everyone’s a Programmer’? ¦ Interesting Intel VPUs

Home » Latest News Releases » Sonatype Expands its Fully Automated Open Source Security and Governance Solution to Support C/C++, PHP, and Ruby

Sonatype Expands its Fully Automated Open Source Security and Governance Solution to Support C/C++, PHP, and Ruby

By: Deborah Schalm on March 12, 2020 2 Comments

Nexus Lifecycle now allows users to scan applications for open source software vulnerabilities, automatically enforce open source governance policies, and easily remediate open source risk for 27 different languages and package formats.

Recent Posts By Deborah Schalm
  • Exabeam Reinvents Security Analytics with Fusion XDR and Fusion SIEM Cloud Products to Address Security Needs at Scale
  • New Study Reveals Importance of Optimized Strategy for the Selection, Support, and Maintenance of Open Source Software
  • Applitools Integrates With Rally for Fast and Automated Bug Management
More from Deborah Schalm
Related Posts
  • Sonatype Expands its Fully Automated Open Source Security and Governance Solution to Support C/C++, PHP, and Ruby
  • Sonatype Strengthens Continuous Delivery with New Atlassian Integrations
  • Sonatype Delivers Premium Open Source Controls to GitHub Users
    Related Categories
  • Latest News Releases
    Related Topics
  • sonatype
Show more
Show less

Fulton, MD – March 12, 2020 — Sonatype, the company that scales DevOps through open source governance and software supply chain automation, today announced it’s further expanded its language coverage within Nexus Lifecycle to include Conan (C/C++), Composer (PHP), and RubyGems (Ruby), including the ability to create and contextually enforce policies. By continuing to increase support for the most popular component formats, Nexus Lifecycle is helping millions of developers and security professionals to automatically govern open source hygiene across every phase of the software development lifecycle (SDLC).

With the addition of C/C++, PHP, and Ruby, Nexus Lifecycle now supports 27 programming languages and package formats, further meeting the diverse needs of enterprise development teams.

According to Sonatype’s 2019 State of the Software Supply Chain Report, 1 in 10 open source components downloaded by development teams had known security vulnerabilities. This doesn’t represent the number of components that will be discovered as vulnerable over time, nor potential open source licensing risk, about which organizations should also be concerned. The ability to automate open source governance, enforce policies, and remediate vulnerabilities is vital to application security in today’s world. In fact, the same report showed that managed software supply chains reduced the percentage of vulnerable components used in finished applications by 55%.

“Organizations keep software applications safe, not by chance, but by preparation, and in many cases supported by automation. But, automation without accuracy can be detrimental, giving a false sense of security,” said Brian Fox, CTO of Sonatype. “Developers need broad and accurate component intelligence they can trust for proper security hygiene. By extending our coverage to even more languages, we’re providing our customers with more reliability and confidence, while increasing productivity.”

Organizations using Nexus Lifecycle and C/C++, PHP, and Ruby will now be able to:

  • Create custom security, license, and architectural policies and contextually enforce those policies across every stage of the SDLC
  • Select safer components throughout the software supply chain, and reduce risk
  • Automatically enforce policies and view expert remediation guidance in the tools developers use every day

Sonatype remains committed to creating the most universally applicable, polyglot software supply chain automation tools. This is just one of many releases dedicated to expanding the languages with native support across the Nexus Platform.

Additional Resources: 

  • Read more about Sonatype’s Nexus Lifecycle’s support for C/C++, PHP, and Ruby on our blog
  • Check-out why Nexus Lifecycle is continuously #1 on IT Central Station for enterprises

About Sonatype

Sonatype is the leader in software supply chain automation technology with more than 350 employees, over 1,000 enterprise customers, and is trusted by more than 10 million software developers. Sonatype’s Nexus platform enables DevOps teams and developers to automatically integrate security at every stage of the modern development pipeline by combining in-depth component intelligence with real-time remediation guidance. For more information, please visit Sonatype.com, or connect with us on Facebook, Twitter, or LinkedIn.

Filed Under: Latest News Releases Tagged With: sonatype

« Atlassian Adds No-Code Automation Tool to Jira Cloud
Catchpoint Provides Free Remote Monitoring Tools to Help Combat COVID-19 Pandemic »

Techstrong TV – Live

Click full-screen to enable volume control
Watch latest episodes and shows

Upcoming Webinars

Securing Your Software Supply Chain with JFrog and AWS
Tuesday, June 6, 2023 - 1:00 pm EDT
Maximize IT Operations Observability with IBM i Within Splunk
Wednesday, June 7, 2023 - 1:00 pm EDT
Secure Your Container Workloads in Build-Time with Snyk and AWS
Wednesday, June 7, 2023 - 3:00 pm EDT

GET THE TOP STORIES OF THE WEEK

Sponsored Content

PlatformCon 2023: This Year’s Hottest Platform Engineering Event

May 30, 2023 | Karolina Junčytė

The Google Cloud DevOps Awards: Apply Now!

January 10, 2023 | Brenna Washington

Codenotary Extends Dynamic SBOM Reach to Serverless Computing Platforms

December 9, 2022 | Mike Vizard

Why a Low-Code Platform Should Have Pro-Code Capabilities

March 24, 2021 | Andrew Manby

AWS Well-Architected Framework Elevates Agility

December 17, 2020 | JT Giri

Latest from DevOps.com

Chronosphere Adds Professional Services to Jumpstart Observability
June 2, 2023 | Mike Vizard
Friend or Foe? ChatGPT’s Impact on Open Source Software
June 2, 2023 | Javier Perez
VMware Streamlines IT Management via Cloud Foundation Update
June 2, 2023 | Mike Vizard
Revolutionizing the Nine Pillars of DevOps With AI-Engineered Tools
June 2, 2023 | Marc Hornbeek
No, Dev Jobs Aren’t Dead: AI Means ‘Everyone’s a Programmer’? ¦ Interesting Intel VPUs
June 1, 2023 | Richi Jennings

TSTV Podcast

On-Demand Webinars

DevOps.com Webinar ReplaysDevOps.com Webinar Replays

Most Read on DevOps.com

What Is a Cloud Operations Engineer?
May 30, 2023 | Gilad David Maayan
No, Dev Jobs Aren’t Dead: AI Means ‘Everyone’s a Programmer’? ¦ Interesting Intel VPUs
June 1, 2023 | Richi Jennings
Forget Change, Embrace Stability
May 31, 2023 | Don Macvittie
Five Great DevOps Job Opportunities
May 30, 2023 | Mike Vizard
Checkmarx Brings Generative AI to SAST and IaC Security Tools
May 31, 2023 | Mike Vizard
  • Home
  • About DevOps.com
  • Meet our Authors
  • Write for DevOps.com
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • Privacy Policy

Powered by Techstrong Group, Inc.

© 2023 ·Techstrong Group, Inc.All rights reserved.