Security teams don't have a visibility problem. They have a software decision problem.
The @sdtimes Editorial Board captured that shift in this year's SD Times 100, recognizing @sonatype alongside other organizations helping development and security teams build with greater
Every AI system has a supply chain and models are only part of the picture. Datasets, open source components, APIs, and agents all shape how AI behaves and where risk can emerge.
Great insights from @KateOflaherty and @llkkaT:
🔗 insight.scmagazineuk.com/what-is-an-ai-…
New React2Shell RCE vulnerabilities highlight a growing challenge for every modern software organization: the expanding risk surface created by generative and agentic AI-accelerated development.
Even widely trusted frameworks like React and Next.js can introduce pathways for
Application security is moving fast. Is your team keeping up?
Gartner’s new “Hype Cycle for Application Security, 2025” reveals the strategies leading organizations use to cut security incidents by up to 70%—without slowing their release cycles.
Ready to stay ahead of emerging
Nexus Repository Cloud helps you stay one step ahead by detecting malware in both open source components and AI/ML models — directly in your proxy repository.
Add Sonatype Repository Firewall to block and remove risky packages before they ever hit your pipeline.
🛡️ Built for