"Sonatype Nexus Platform", a tool for realizing and automating DevSecOps

■ This is an article posted on June 2020, 11, so the content of the information may be out of date.

Tools for implementing and automating DevSecOps on the Unipos website Sonatype Nexus Platform Page has been added.

Sonatype Nexus PlatformIs a product group that protects the entire software development life cycle and realizes and automates DevSecOps (*).

* What is DevSecOps?

DevOps, one of the software development methods in which the development team and the operation team work togetherDevelopment+Opgenerations), Security (Security) added concept.

At Sonatype, we focus on helping every organization continue to take advantage of the benefits of open source components without risk, and we are developing a range of products to help them achieve that. ..

At Unipos, among those products, the repository manager Nexus Repository Pro, Firewall against risky OSS Nexus firewall, A tool to bring continuous security to the entire software supply chain Nexus Lifecycle , We are dealing with these enterprise Nexus solutions.

Available Products

Nexus Repository Pro

A repository manager that manages binaries and build artifacts throughout the software supply chain.Manage components from development to delivery, including binaries, containers, assemblies, and finished products.

It supports build tools such as Maven / Java, npm, NuGet, Helm, Docker, P2, OBR, APT, GO, R, Conan.

* Operation image

 

Nexus Repository Pro Features
– Staging and release functionality
– High availability
– Advanced security options
– Component intelligence via Repository Health Check
– World class enterprise support

Nexus Firewall

A tool to prevent vulnerable open source components from entering the system development life cycle and risking the software supply chain.

It supports various languages ​​such as Java, JavaScript, .NET, Python, Go, Ruby, RPM.

* Operation image

 

Nexus Firewall Features
– Always-on component intelligence
– Custom policy creation
– Automatically manage security and license risks
– Advanced reporting capabilities
– World-class enterprise support
- Supports Nexus Repository and jFrog's Artifactory

Nexus Lifecycle

A tool to bring continuous security to your entire software supply chain.
At every aspect of the system development life cycle, we continually identify risks, apply policies, and fix vulnerabilities.

It can work with Nexus Repository, Artifactory, GitHub, GitLab, IDEs, Jira, Jenkins, Azure DevOps, Micro Focus Fortify, Xebia Labs, OpenShift, Mesosphere OS, AWS, Docker and more.

* Operation image

 

Nexus Lifecycle Features
– Real-time component intelligence integrated with existing tools
– Dashboards, detailed reporting, and tool-level interfaces
– Advanced application monitoring
– World-class enterprise support

Each product isLicense agreement with annual renewal.
One license is required for each user, so please let us know the number of users (number of licenses) when making inquiries.