Log inSign up
Sonatype
15.9K posts
Sonatype profile banner
@sonatype

Sonatype

@sonatype
Helping developers build with confidence. Stewards of Maven Central.
sonatype.com
Joined February 2010
898
Following
10.5K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @sonatype
    Sonatype
    @sonatype
    Sep 3
    A security headline tells you what happened. Security Events helps answer the harder questions: Are you affected? What should you check? What happens next? Your first stop for major vulnerabilities and malicious package incidents:
    guide.sonatype.com
    Security Events | Sonatype Guide
    Browse security advisories and threat intelligence from Sonatype Security Research. Get authoritative analysis of major CVEs, supply chain attacks, and malware…
  • @sonatype
    Sonatype
    @sonatype
    Aug 21
    91 Spring CVEs. 209,569 affected components. And counting. The hard part isn’t knowing new vulnerabilities exist. It’s figuring out what actually affects your software. Guide turned a massive coordinated disclosure into something developers can act on ↓
    guide.sonatype.com
    91 Spring CVEs Affect More Than 148,000 Co… | Sonatype Guide
    Broadcom published a large collection of Spring security advisories affecting Spring Framework and related projects, with Sonatype tracking 91 CVEs and more th…
  • @sonatype
    Sonatype
    @sonatype
    Jul 20
    Security teams don't have a visibility problem. They have a software decision problem. The @sdtimes Editorial Board captured that shift in this year's SD Times 100, recognizing @sonatype alongside other organizations helping development and security teams build with greater
    Image
  • @sonatype
    Sonatype
    @sonatype
    Jul 16
    Every AI system has a supply chain and models are only part of the picture. Datasets, open source components, APIs, and agents all shape how AI behaves and where risk can emerge. Great insights from @KateOflaherty and @llkkaT: 🔗 insight.scmagazineuk.com/what-is-an-ai-…
    Image
  • @sonatype
    Sonatype
    @sonatype
    Dec 4, 2025
    New React2Shell RCE vulnerabilities highlight a growing challenge for every modern software organization: the expanding risk surface created by generative and agentic AI-accelerated development. Even widely trusted frameworks like React and Next.js can introduce pathways for
    lnkd.in
    LinkedIn
    This link will take you to a page that’s not on LinkedIn
    1
Advertisement
Advertisement