The major use case for Nexus Repository is for open source libraries and third-party libraries scanning. It will give you the vulnerabilities and security vulnerabilities of these third-party libraries. This is how we use it.
Sonatype Repository Firewall ensures secure software supply chains by inspecting open-source components for vulnerabilities and other threats at the point of ingress.



| Product | Mindshare (%) |
|---|---|
| Sonatype Repository Firewall | 1.1% |
| SonarQube | 12.4% |
| Checkmarx One | 8.2% |
| Other | 78.3% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Application Security Tools | Jul 23, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Jul 23, 2026 | Download |
| Comparison | Sonatype Repository Firewall vs SonarQube | Jul 23, 2026 | Download |
| Comparison | Sonatype Repository Firewall vs Checkmarx One | Jul 23, 2026 | Download |
| Comparison | Sonatype Repository Firewall vs Veracode | Jul 23, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| SonarQube | 4.0 | 12.4% | 84% | 137 interviewsAdd to research |
| Snyk | 4.1 | 5.0% | 100% | 51 interviewsAdd to research |
Designed for real-time protection, Sonatype Repository Firewall not only identifies but also controls potentially malicious, vulnerable, or non-compliant components before they reach development teams and CI/CD pipelines. It offers automation for quarantine, blocking workflows, and integrates with repository managers like Sonatype Nexus Repository to enforce security and compliance policies. Audit trails and reporting features enable monitoring of repository health and trends while automated remediation workflows assist security and DevOps teams in reducing manual intervention.
What are the notable features of Sonatype Repository Firewall?
What benefits or ROI can users expect?
Sonatype Repository Firewall is widely implemented across industries that rely on rapid and secure software development. It is particularly valuable in sectors like finance, healthcare, and technology, where managing software dependencies effectively is crucial for maintaining security and compliance standards.
Sonatype Repository Firewall was previously known as Sonatype Nexus Firewall, Nexus Firewall.
EDF, Tomitribe, Crosskey, Blackboard, Travel audience
| Author info | Rating | Review Summary |
|---|---|---|
| Lead Cybersecurity Analyst at Saudi Aramco | 3.0 | I use Sonatype Nexus Repository for scanning third-party libraries for vulnerabilities, finding its security posture excellent and reliable. While costly, it's worth it. I wish for waiver notifications and reminders, but overall, I rate it highly at nine. |
| Cloud ARchitect at a tech vendor with 10,001+ employees | 4.5 | I use Sonatype Repository Firewall to block vulnerable and malicious code in real-time, enforcing policies and speeding development. It's stable and scalable, but I recommend AI integration, more granular policy control, and better DevOps integration, while addressing occasional false positives. |
| Lead Cybersecurity Analyst at Saudi Aramco | 3.0 | I find Sonatype essential for managing open-source and third-party library vulnerabilities, integrating with CI/CD, and maintaining security. Its stability and support are good, but I wish for improved waiver notifications and lower pricing. |
| CEO at VIVANS | 4.0 | We use Sonatype Repository Firewall to prevent malicious packages in Nexus Repository, as it supports accurate detection via its database. While lacking in container and AI support, improvements are expected in 2025. Alternatives are limited to Gather. |
| Global Treasurer at Genpact | 4.5 | I use this tool for essential QA automation and code quality, finding it easy to use with excellent ROI in our CI/CD. While initial setup took effort, I wish it supported more languages and offered better free customer service. |
| Senior Cyber Security Architect and Engineer at a computer software company with 10,001+ employees | 4.0 | I find Sonatype crucial for open-source security, providing vital vulnerability detection and boosting developer productivity. Though initial setup was challenging and phone support is absent, its stability and responsive email support are highly valued. |
| Student at a university with 51-200 employees | 4.0 | I find Sonatype Repository Firewall valuable for vulnerability and security assessments, with strong network and intrusion protection features as well as compliance rules. However, improvements are needed in file systems, and a zero test feature should be included. |

The major use case for Nexus Repository is for open source libraries and third-party libraries scanning. It will give you the vulnerabilities and security vulnerabilities of these third-party libraries. This is how we use it.
The biggest advantage of Sonatype is that you get an idea about the open source or third-party libraries vulnerabilities, including if there are any fixes for them and if it is utilized in our environment. Because there are many types of vulnerabilities, they call it composition, and it just gives you an idea of the security posture of your used libraries, third-party libraries, and open source components. Imagine if it was not there; how would you find out what is happening? That is because it is really significant. You get the vulnerability and what it is doing. Recently, we acquired Sonatype Repository Firewall, so you can block things and allow things, which is very useful for security.
The Health Check feature for repositories is for identifying vulnerabilities. Identifying vulnerabilities normally comes from the tool itself. It will mark something as vulnerable.
For Sonatype, they have a feature for waiving. Suppose you have something vulnerable, and this component cannot be fixed due to some other limitations. The severity of the vulnerabilities varies based on where it is, such as Internet-facing or air-gapped, and that affects the severity. If you have other controls and other measures, there is this feature in Sonatype, which is a great feature, where if the developer or user believes this is a false positive, or if they believe that this vulnerability can be fixed in a month or two due to restrictions and other compensating controls, this feature is amazing. However, I wish Sonatype would allow notifications. It gets stored in the system without notifications, so if Sonatype works on notifying us, the security team, that there is a waiver there and to look into it, that would be great because otherwise, we need to rely on users to tell us via emails, or we check ourselves, which requires reminders. The other thing is that sometimes you can waive it for one month, two months, or whatever when we agree on this. If Sonatype invests in reminders about when this waiver will be ending for the user and for us, that would be great.
I am not aware if Nexus Repository is scalable, as I have not participated in this. However, it serves our purpose.
I started using Sonatype Nexus Repository before 2023, possibly in 2022 or 2019, but I do not have the exact dates because I was not involved in that process when they brought it in.
Nexus Repository is reliable, without a doubt.
My impression of Sonatype's customer support and technical service is positive.
I would rate Sonatype's support a nine on a scale from zero to ten.
I have not worked with any other competitors for the same use case, so I cannot really say something here. I cannot compare it at this time, but I know they are one of the top ones in the market.
Sonatype's installation process and deployment procedure is interesting because we have people who purchased it. There are many features that are not security-related. There are policy administrators or security administrators, that is us, but there is another team doing all of that. I am not sure how complex it is, but I know they stay after hours to do that. I did not participate in something like that to tell, but I understand the complexity involved.
We are customers of Sonatype. We get the product, we use the product, and we buy the product.
Buying Sonatype is eventually worth it because time definitely has great value, and security is a requirement as well. Generally, everyone prefers cheaper options. However, at the end of the day, you are going to pay for what you have to.
The price for the Sonatype product is on the high side. From what I heard, some components such as Sonatype Repository Firewall are very expensive. However, security can be an expensive thing. It is not cheap. This is not a cheap tool.
Hosting, proxying, and grouping repositories have a major benefit for any organization because it centralizes the information. Now you know what you have and what you do not have. You also have control over it, and you know the security posture of it. This helps you maintain a secure environment.
Sonatype helps with development environments because there are use cases for when someone needs one of these frameworks. You connect with the third-party libraries, and then we can have these libraries stored here. Not just stored, we also know the health of it and how it is doing. Sometimes, we have zero attacks with that through live checks, and we get that feedback.
Health checks contribute to our identification procedure by checking if that is really a vulnerability or not. For example, if we have a vulnerability in that library, it does not necessarily mean the whole library is vulnerable because of one function. This library is used in the code that we have, but that specific vulnerable function is not present. In that scenario, we check if it applies to what we have or not.
For assessing lifecycle management integration with CI/CD pipelines, there are other tools we use. We have Fortify integrated into the pipeline. When you run the pipeline, part of it is the scanning. When you run that, you get the vulnerabilities and the issues that you have in this pipeline.
I would rate this product a nine overall.

My main use case for Sonatype Repository Firewall is to check dependencies for vulnerabilities, block any download content that poses a risk, and enforce and adhere to security policies in real-time. I check for any suspicious activity and prevent vulnerable and malicious code from entering the build. When application teams create images, I check for vulnerabilities, block critical and vulnerable-level content, and block packages if someone tries to download unauthorized images or engages in suspicious activities using vulnerability intelligence.
An example would be when a developer is building a Java-based application with Maven. As they write code and add dependencies, the build tool requests a package from Sonatype Repository Firewall, which is integrated with the proxy repository that connects to the internet to download packages. During this process, whenever a request goes to the Nexus repository, Sonatype Repository Firewall checks the component before downloading it. If any vulnerability is detected, such as one related to Log4j, the policies applied at the firewall level help block the component containing critical severity vulnerabilities. The actions taken include blocking the download, putting the component into quarantine, and informing the developer that it was locked due to a critical vulnerability.
Sonatype Repository Firewall immediately identifies vulnerable content and helps block it promptly. It stops bad components before they ever enter my environment and helps developers choose correct and safer versions. It detects problems early rather than after accidents happen, and applies automatic enforcement of policies. This protects against threats and helps reduce human errors.
The automatic enforcement happens at different stages. For instance, if an application team requests any dependency to the Nexus Sonatype repository proxy, it first goes to the firewall, which intercepts it before downloading and checks for vulnerabilities, malware signals, and policy rules. If safe, it allows the dependency to be downloaded. If anything risky is found, it blocks it instantly without human intervention. Once a component is downloaded, it gets stored in the cache, allowing faster downloads in the future since the component is already available in the local repository.
Since I started using Sonatype Repository Firewall more than five years ago, it has had a positive impact on security and development speed. It helps prevent security incidents, fixes vulnerabilities early, and enables stable releases for applications. It speeds up development with safer dependencies by eliminating manual security checks and helps reduce human error and knowledge gaps, standardizing my DevOps pipeline and framework according to security guidelines.
I recommend integrating artificial intelligence capabilities into Sonatype Repository Firewall for real-time intelligence updates regarding security risks. I also suggest enhancing policy control for improved granular policy settings and better integration with DevOps pipelines, especially in container-based workflows.
I find the documentation very good as I often refer to it for information. The user interface is also very good, but I have noticed some false positives where safe components get blocked, causing unnecessary delays for developers.
I have been using Sonatype Repository Firewall for over three years.
Sonatype Repository Firewall is stable, and although I explored alternatives like JFrog Artifactory and JFrog X-ray, I did not find them as valuable for my organization.
My product runs on a container-based platform on AWS, utilizing auto-scaling to handle distributed traffic. The policies are enforced in a stateless manner and shared across the system, which helps manage load on the primary nodes effectively during high traffic.
My experience with customer support has been minimal since I have not faced significant issues, and any past support requests during migration were handled well.
Sonatype Repository Firewall is stable, and although I explored alternatives like JFrog Artifactory and JFrog X-ray, I did not find them as valuable for my organization.
I advise others considering Sonatype Repository Firewall to ensure they have strong organization-wide policies that comply with security regulations. This product can handle large volumes of data and scale as needed, offering excellent scalability and security features. It is a good product, and I encourage others to use it for large-scale applications if they wish to implement it. I have rated this product 9 out of 10.

The major use case for Sonatype Repository is for open-source libraries, third-party libraries, and scanning. It gives you the vulnerabilities and security vulnerabilities of these third-party libraries.
In terms of lifecycle management and integration with CI/CD pipelines, we assess the pipelines with Fortify integrated into part of the pipeline. When you run the pipeline, part of it is the scanning, and you get the vulnerabilities and the issues in this pipeline.
The biggest advantage of Sonatype is that you get an idea about the open source or third-party libraries vulnerabilities. You know if there are any fixes for them and if it is utilized in our environment. It gives you an idea of the security posture of your used libraries, third-party libraries, and open source components. It also shows you the vulnerabilities and what is being done. Recently, we acquired Sonatype Repository Firewall, which is very useful for security because you can block things and allow things.
The Health Check feature for repositories is for identifying vulnerabilities, basically. It normally marks something as vulnerable, but it also checks if it is accepted or not.
Health checks contribute to my identification procedure because if we have a vulnerability, some vulnerabilities are in that library, but it does not necessarily mean that the whole library is vulnerable because of one function that might not be in our code. So I check if that is really a vulnerability or not.
The ability of Sonatype to manage NPM, Docker, and Maven helps us with development environments because if someone needs one of these frameworks, we can connect with third-party libraries and have them stored here. We also know the health of it and sometimes receive live checks and feedback.
Hosting, proxying, and grouping repositories have a major benefit by being centralized for our organization. You know what you have and what you do not, and maintain a secure environment, knowing its security posture.
For Sonatype, there is a feature for waiving a vulnerable component that cannot be fixed due to limitations. However, I wish Sonatype would improve notifications regarding waivers, so the security team knows to look into it instead of relying on user emails or checking ourselves.
I think the price for the product is on the high side, as some components are very expensive, such as Sonatype Repository Firewall. It is not a cheap product, but security can come at a cost.
Time definitely is saved because security is a requirement, and it provides great value, although everyone likes things to be cheaper. But at the end of the day, you pay for what you have to.
I started using this product before 2023, possibly in 2022 or 2019, but I do not have the exact dates because I was not involved in that process when they brought it in.
Sonatype Repository is reliable and stable.
My impression of customer support and technical service from Sonatype is positive.
I would give them a nine for support on a scale from zero to ten.
The installation process and deployment procedure for Sonatype is complex because the administration team handles that, and I know they stay after hours to do it, but I did not participate to know the details.
We are customers of Sonatype; we get the product, we use it, and we buy it.
I have not worked with any competitors yet, so I cannot compare Sonatype to anything right now, but I know they are one of the top ones in the market.
Sonatype is pretty much a leader and stands out in their field.
We have it on-premises; all is on-prem because sometimes the offerings of the cloud are not here in our country. The cloud area is still evolving, and we are not cloud-based yet.
Many companies, including ours, use Nexus Repository due to concerns about malware and critical vulnerabilities. There should be a specific method to prevent malicious packages from entering the internal network, so our company uses Nexus Repository. We usually consider adding the firewall feature on top of the Repository, with the main purpose being to block malicious packages.
The firewall is the only solution that supports Nexus Repository. This firewall comes with an accurate database, which can identify most malicious code from entering. It relies on the Sonatype accurate database, so the accuracy is excellent. There is no other option except Sonatype deploy to the firewall.
There are several features lacking in the current offering, particularly concerning container support and AI packages, like humming phase support. However, I have heard that it is on the roadmap for 2025.
I have been using this solution for four years.
It is software, so there is always a possibility of bugs, however, they are quite fast in fixing these bugs. It is quite stable.
There is an option to scale the capacity using an external database, and then you also have support. I do not think there is any issue with scalability.
The customer service is fantastic. They provide the required responses and relevant support, which is the biggest advantage of using Sonatype.
Positive
I do not have handling experience with another firewall. Sonatype Firewall is the only one I have been using. There is only one other alternative.
The initial setup is quite straightforward and easy. It is not complicated.
Just a couple of staff members can complete the installation and configuration.
Also, I consider it average. Some people might consider it expensive, however, since it supports many beautiful features, I would say it is worth it.
We looked at Sonatype or Gather. There are not that many options.
I would give the solution eight out of ten. I would look at the comparison of Sonatype to some other firewalls. There is room for improvement, especially mentioning container support and AI packages.

We use this tool for QA automation and QA quality checking. We check the quality of the code and the calls with SonarQube. If there is any kind of memory leak, it protects against that. When we want to move the code to the next level, we use Sonar Quality Gates. This is part of a QA automation process.
We only then promote the code to UAT and then the product once it passes 80% of the threshold that we set for it.
I believe this tool is being used by most of the product development team in the organization. It's part of the CI/CD pipeline. You can say it's a must-have kind of tool. Some other tools are commercially available, but using this as a freeware and commercial tool, it's really a good tool to have.
For the QA team, it's a really good tool.
For those who are not on the QA team, it is also a good tool to use for SDL in the SDLC. It plays a very critical role of doing the automatic quality check recommendation. Meaning, when using this tool, people can easily rectify the issues in the environment itself, instead of going to a higher environment and identifying them.
This tool is quite easy to use and learn. We decided that there was no need to hire anyone new who would specialize in this. We had a team of about five to ten people who learned how to use this tool. There are some other automation tools like Jenkins, for example, that require a lot of effort to configure and write out the code, but you do not need to do such for this tool. I thought outside of the box and saw that there are many options available to us when using this tool. The plugins are there, you can download and use the tool at ease and you do not need to do any kind of development. Overall, it’s quite easy to use.
I suggest that Sonatype should add support for more computer languages. The product works well with languages such as Java and C#, but in my opinion, adding support for more languages would be really good. In addition, I believe that they should add some more functionality to improve the quality of the code.
I used the product for two or three projects, for about two and a half years, and the product is still a part of my company’s CI/CD pipeline. Although I am not managing it anymore, the support team and the whole development team are still using this tool.
From a scalability point of view, it's good. However, we were not heavily using this product so I cannot comment further about the scalability of this product.
I think we posted one or two queries on the development side, but the response was not that great. This may be due to the fact that we were not paying customers at the time.
Later on we bought some licenses. For license users, I think the support is good. For those who are using the open source version, it might take some time to get a proper response.
Positive
The setup is straightforward, but it is important to understand the tool first. For example, which functionalities you need to check and which plugins need to be installed.
Product-wise, it's quite easy, and people can deploy it. However, configuration and setting the functionalities, etc. is quite a challenge. You will have to learn more about these features, depending on how effectively you would like to use this product.
It took some time, one or two months, to set it up. The team had to configure the project, set up the proper quality case, and choose the correct options, which are the functionalities you want to use for this product or your own product. It’s a process that continuously improves.
We constantly check for upgrades and new versions of the product. We upgraded this product once or twice in the past and it was quite easy and we did not face any issues when doing so.
It definitely adds value to the code quality. In the long run, you will definitely get a good ROI. You will get clean code every time, and that's a great achievement. You won't face any issues in the production environment related to quality and bad coding. It's really, really good and helps our organization get a good ROI. I believe that a good ROI is very important.
The licensing is quite reasonable, I believe. I do see that it adds value. It means whatever part you want to use, you can just use that part and pay for that. I think the licensing is fair enough.
It’s good for long-term users. Using this product on a yearly basis would be great. However, if your development cycle is only two or three months long, you will likely want to go with the monthly basis only.
With the security concerns around open source, the management and vulnerability scanning, it's relatively new. In today's world more and more people are going through the open source arena and downloading code like Python, GitHub, Maven, and other external repositories. There is no way for anyone to know what our users, especially our data scientists and our developers, are downloading. We deployed Sonatype to give us the ability to see if these codes are vulnerable or not. Our Python users and our developers use Sonatype to download their repositories.
Given the confidentiality of our customer, we keep everything on-prem. We have four instances of Sonatype running, two Nexus Repositories and two IQ Servers, and they're both HA. If one goes down, then all the data will be replicated automatically.
We have visibility into what developers are downloading now. We had an incident recently where a few of the packages from PyPI were vulnerable, and we knew. Another example is that we were working on an open source project, enterprise-wide, and we wanted to do a PoC. When the company doing the PoC started downloading the packages, even they didn't know that those packages were vulnerable. Sonatype detected that.
Nexus Firewall has also significantly improved the time it takes us to release secure apps to market. Before, we needed to manually do a security evaluation for the static and dynamic code. While Sonatype does not do static analysis, it's been fine for dynamic. We don't have the headache of worrying about what our developers are downloading. Sonatype is taking care of all that. We have a very closed environment; nothing is allowed. Everything is "deny, deny." It used to be that for a user to request a package from PyPI, for example, they would need to submit a firewall request and to go through a CRV meeting. People would need to review it and approve it or reject it. Once that was done, we would need to whitelist that URL into the proxy. To download simple packages it would take users two weeks. Now, they can do it instantly.
It has helped developer productivity because they can do things right away now. For the majority of the code they're downloading, the URLs are already whitelisted through Sonatype. Our development has been pretty fast, as a result. Overall, the executives have been happy, because now we have something that is evaluating the open source code.
The Nexus Firewall itself, with its sheer ability to ensure that you're downloading safe code, is a big win for our environment.
Another thing that I like about Sonatype is that if you download something today, and five days from today it becomes vulnerable, it will notify you.
When you go to the IQ Server dashboard, it will tell you, "Version 1.2 is not good. You should upgrade it to version 1.3." You have that visibility, and you can whitelist things based on your business justification, and you can add notes in there as well.
In terms of securing our software supply chain, what we're trying to do is set things up so that they're upstream from our developers' work stations. Aside from downloading the code safely through Sonatype, a second way is by pushing our developers' code into a repository and Sonatype will do the security evaluation. You can use it as a hosted repository, versus using ADO which does not provide security evaluation and scanning. It helps bring open source intelligence and policy enforcement across our SDLC.
I've been using Sonatype Nexus Firewall for two years.
The stability has been okay. I can't complain. It hasn't broken down on us.
It hasn't been hard to scale it. We're in the process of integrating with ADO and our CI/CD pipeline.
At the moment, any developer who needs to download anything from the open source world must do so through Sonatype. All other access is blocked on the servers themselves. The servers cannot directly go through to PyPI, for example. Everything has to go through Sonatype. I can confidently say that we are using it enterprise-wide and everything is coming through Sonatype.
I love the product and the team, and their support is phenomenal. You send them an email and they reply back to you within minutes. In general, they're responsive and helpful.
The guys from Sonatype who helped me build our dev environment for the PoC were on the ground with us, helping, running around the room, talking to people, and implementing it. But for the production, we had to do everything on our own.
If I have any questions in terms of implementation, or any high-level ideas, the guys from the customer success team that I'm good friends with, throughout this process, always schedule a time to meet or call. It does take them time, but they always make themselves available.
What I don't like is the lack of an option to pick up the phone and call someone for support. That is something they need to improve on. They need to have a professional services package, or they need to include that option with their services. If something breaks at the customer that we work with, I should be able to call someone at Sonatype, get them on the line, share a screen, and fix it right away. They don't have that at the moment.
We did not have a previous solution. This was the first solution we were introduced to. Open source security is new to everyone, and recently were finding a lot more security vulnerabilities in the open source stack. We saw what Sonatype was capable of, we saw that it was blocking stuff. We saw that we had a log of user XYZ downloading this package and, when it was blocked, we were able to whitelist it or blacklist it, and provide a justification for why it was blocked. So far, everything has been pretty good.
For people who don't have a lot of Linux knowledge—including myself, I'm purely a Windows guy—it can be very tricky. It did take us a long time to stand up the environment.
The fact they don't have professional services to implement it for you is a big gap. I have a good relationship with everyone on the Sonatype team. I sent them an email and they made time to jump on a call and help us build it. That is what is expected from a large, enterprise-level company. We have Azure Sentinel and F5 and these companies have professional services. They help you from end-to-end, starting with the implementation. Sonatype does not have been at the moment. It does become challenging when you're not a Linux guy and you need to learn and implement it and to make sure that you're deploying it securely.
To be fully ready, it took us two months. I was involved, along with one of my engineers, and we had the help from Sonatype team.
In terms of an implementation strategy, we had the whole high-level architecture set up, which was not very hard. But to engineer it and do it was a little challenging for me, but it could be different for people who have Linux knowledge.
There are about 200 people using it across our organization. Most of them are developers and data scientists. I take care of the day-to-day maintenance. The upgrades are easy, the directions are easy. If you do need help, you can reach out to the support.
From a security perspective, it has made a significant difference.
The pricing is reasonable if you're a large enterprise developing code. It's not super-expensive. There are no costs in addition to the standard fees.
I know there are others in the market, like JFrog, but it was quite an easy setup and then we just rolled with it. We didn't really bother looking at other products.
You should have some knowledge of Linux before implementing it, because to set up the rsync and to make sure your data is being replicated and that it's HA, you need to know Linux.
We took a look at the demo of Nexus Container and, although I haven't used it hands-on so I cannot say too much about it, it looks like a freaking awesome product. We are in the process of evaluating it and may do a PoC. It looks like it's easy to use, easy to integrate, and does not require a lot of RAM or storage. You can install it on existing Kubernetes clusters, so there's not a lot of infrastructure needed. Using it, I expect we'll find out if the images that we're downloading for the containers are secure or not. It's definitely worth taking a look at it.
Default policies are never really a good idea, anywhere. You need to adjust them based on your environment's needs. When we deployed Sonatype, the policies were not automatically configured so that if a packet is malicious it would block it. You need to manually set those up. But their policy engine provided the flexibility that we need. It was really a quick, easy setup.
The biggest lesson I've learned from using Sonatype is that open source security is very important and it's getting crazy these days, because there's so much hacking and so many breaches going on, so much vulnerability. Even Microsoft codes and some of the packages in PyPI are not secure. You trust a repository like Microsoft or PyPI, but there are still some vulnerabilities out there. That is why it was so important for Sonatype to be implemented in our environment.
The product helps with vulnerability and security assessment. It also helps with assessment at the configuration level.
The product's network and intrusion protection features are valuable. It also has rules and compliance features for security.
The tool needs to improve its file systems. The product should also include zero test feature.
I have been working with the solution for eight years.
I would rate the solution an eight out of ten.