Sonatype Repository Firewall is a cloud-based security solution designed to safeguard your software supply chain against malicious components. It operates by meticulously scanning and evaluating each new component against customized governance policies, thereby effectively identifying and blocking potential threats before they infiltrate your development pipeline. What sets Sonatype Repository Firewall apart is its user-friendly setup, seamless integration with existing workflows, and remarkable scalability, making it suitable for software development environments of any size. Key features include blocking malicious components through behavioral analysis, malware scanning, and vulnerability assessment, as well as the ability to enforce custom governance policies. By utilizing this tool, organizations can enhance their software supply chain security, mitigate risks related to supply chain attacks, bolster compliance with industry standards, and ultimately reduce costs associated with security incidents.
Product | Market Share (%) |
---|---|
Sonatype Repository Firewall | 0.5% |
SonarQube Server (formerly SonarQube) | 20.8% |
Checkmarx One | 10.2% |
Other | 68.5% |
Sonatype Repository Firewall was previously known as Sonatype Nexus Firewall, Nexus Firewall.
EDF, Tomitribe, Crosskey, Blackboard, Travel audience
Author info | Rating | Review Summary |
---|---|---|
CEO at VIVANS | 4.0 | We use Sonatype Repository Firewall to prevent malicious packages in Nexus Repository, as it supports accurate detection via its database. While lacking in container and AI support, improvements are expected in 2025. Alternatives are limited to Gather. |
Global Treasurer at Genpact | 4.5 | No summary available |
Senior Cyber Security Architect and Engineer at a computer software company with 10,001+ employees | 4.0 | No summary available |
Student at a university with 51-200 employees | 4.0 | I find Sonatype Repository Firewall valuable for vulnerability and security assessments, with strong network and intrusion protection features as well as compliance rules. However, improvements are needed in file systems, and a zero test feature should be included. |