Sonatype Repository Firewall Primary Use Case

Ashish Shukla - PeerSpot reviewer
Global Treasurer at Genpact

We use this tool for QA automation and QA quality checking. We check the quality of the code and the calls with SonarQube. If there is any kind of memory leak, it protects against that. When we want to move the code to the next level, we use Sonar Quality Gates. This is part of a QA automation process.

We only then promote the code to UAT and then the product once it passes 80% of the threshold that we set for it.

View full review »
UJ
Senior Cyber Security Architect and Engineer at a computer software company with 10,001+ employees

With the security concerns around open source, the management and vulnerability scanning, it's relatively new. In today's world more and more people are going through the open source arena and downloading code like Python, GitHub, Maven, and other external repositories. There is no way for anyone to know what our users, especially our data scientists and our developers, are downloading. We deployed Sonatype to give us the ability to see if these codes are vulnerable or not. Our Python users and our developers use Sonatype to download their repositories.

Given the confidentiality of our customer, we keep everything on-prem. We have four instances of Sonatype running, two Nexus Repositories and two IQ Servers, and they're both HA. If one goes down, then all the data will be replicated automatically.

View full review »
KN
Student at a university with 51-200 employees

The product helps with vulnerability and security assessment. It also helps with assessment at the configuration level. 

View full review »
Buyer's Guide
Application Security Tools
April 2024
Find out what your peers are saying about Sonatype, Snyk, Mend.io and others in Application Security Tools. Updated: April 2024.
769,976 professionals have used our research since 2012.