Sonatype Lifecycle Stability

NS
Vice President, Cybersecurity at a financial services firm with 10,001+ employees

Fortify Static Code Analyzer stability has improved and I would give it a ten out of ten.

View full review »
Vishal Dhamke - PeerSpot reviewer
Vice President Application Security North America at BNP Paribas

It is a stable solution, however, the stability of Fortify SAST can depend on the hardware and network infrastructure it's running on. Make sure your infrastructure meets the system requirements recommended by Micro Focus.

You need to properly train your development and security teams on how to use Fortify SAST effectively. Knowledgeable users are more likely to obtain stable and accurate results.

View full review »
JB
Adjunct at University of Maryland

I've never had an issue with the solution crashing.

View full review »
Buyer's Guide
Sonatype Lifecycle
March 2024
Learn what your peers think about Sonatype Lifecycle. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,578 professionals have used our research since 2012.
AA
Sr cyber analyst at a energy/utilities company with 10,001+ employees

From what I have seen so far, it is very stable. It is a browser-based solution. You just log in to the website and see all your applications. From your machine, you can just push, and it will be published there. You click a scan, and your results will be in Fortify Software Security Center. It is straightforward and easy to use.

View full review »
AA
Sr cyber analyst at a energy/utilities company with 10,001+ employees

From what I have seen so far, it is very stable. It is a browser-based solution. You just log in to the website and see all your applications. From your machine, you can just push, and it will be published there. You click a scan, and your results will be in Fortify Software Security Center. It is straightforward and easy to use.

View full review »
VF
Software analyst at a financial services firm

I would rate the stability of Fortify SAST ten out of ten.

View full review »
IV
Product Owner Secure Coding at a financial services firm with 10,001+ employees

It is very stable. There are no complaints. It is good in terms of availability.

View full review »
ME
Sr. Enterprise Architect at MIB Group

I've had no trouble with it. We're currently running it even on a single server and we don't have many problems with it. It seems very easy to move into what we call a high-availability mode. Upgrades to a new version are done within a 30-minute timeframe, so we can easily schedule them.

View full review »
LH
Configuration Manager at a wellness & fitness company with 1-10 employees

The stability is very good. It's extremely stable. We haven't had an instance where it's running out of memory or anything else.

View full review »
RW
VP and Sr. Manager at a financial services firm with 1,001-5,000 employees

It's very stable. We have not had any issues with it.

View full review »
KS
Software Engineer at a manufacturing company with 10,001+ employees

The stability is fine. I have not struggled with it. The solution is working, it's available. But this is something I can't tell you much about it because the server infrastructure and installation are done by our infrastructure team. I'm not sure if they are struggling with availability of the services.

View full review »
WK
Sr. DevOps Engineer at Primerica

The stability has been great. We haven't had any issues in the year that we've had it running. So far, so good.

View full review »
Finto Thomas - PeerSpot reviewer
Information Security Program Preparer / Architect at Alef Education

We've been running for almost a year and a half and have not faced any service degradation or outage. There have been times when we need to upgrade and plan, so I rate the stability a nine out of ten.

View full review »
Finto Thomas - PeerSpot reviewer
Information Security Program Preparer / Architect at Alef Education

Until now, we haven't faced any challenges on the stability front. If there's a challenge, if something is down, we definitely get a direct alert. We are happy with the stability part. Both the software and the infrastructure are good.

View full review »
TW
Security DevOps Engineer at a legal firm with 1-10 employees

I would rate the stability a seven out of ten. Fortify Static Code Analyzer suffers from limitations in handling versioning issues. It necessitates specific guidelines or calls to operate efficiently otherwise it doesn't provide feedback.

View full review »
SS
Engineering Tools and Platform Manager at BT - British Telecom

IQ Server is quite stable. I get a report from my team about the availability of my tools, and IQ Server stands pretty great. Its stability is 99.99% for sure. 

Repo has had some challenges with our setup. I'm not sure if that has to do with Repo itself or our own infrastructure. There have been some challenges, but there is nothing noticeable. So, overall, they have been quite good. The only thing is that whenever we have to update the tool, there has to be mandatory downtime, which I would like to avoid with something like a Kubernetes-based system.

View full review »
RV
Software Architect at a tech vendor with 11-50 employees

The stability is good. We have never had an issue with it being unreachable. I've not noticed any downtime with it. 

The single issue and change that our administrator ran into was that after he setup the solution, it used a file database locally. After he switched it from running in the foreground to running as a service on a VM, we realized that the database was gone, it had somehow reset. He was able to find the previous file used as the database though and successfully migrated the data to Postgres. That was all the way in the start and we noticed the issue right away. After that, we've had no issues with it.

Our system administrator has not had any issues installing updates to IQ Server.

We haven't had any major security things that we had to fix last minute or on production, which is a good thing. However, we have had vulnerability issues come up. We were able to check them out and notice that they wouldn't affect us immediately because they applied to a specific use case which doesn't occur in our application. However, it does show that things come up. Security issues are found, and if we would've done a manual scan with our previous product/project, we may not have known that something happening on production or we would have found it a lot later. Whereas now, these things pop up right away. It has seemingly increased the overall stability and how fast we can respond to things.

We think about software issues in healthcare. We always want to be very careful of security things in this application because of HIPAA and patient privacy and vulnerabilities to applications from things like ransomware. We get questions about this stuff from potential clients about how we can protect ourselves. We have continuous monitoring of security vulnerabilities, which is very good advertisement for our company. This was not something we could say before because we'd have to do it manually. Sometimes, a few months would go by before we could run another scan.

View full review »
AB
Enterprise Infrastrcture Architect at Qrypt

I've never had any problems with it, so it's been very stable.

View full review »
GO
Lead IT Security Architect at a transportation company with 10,001+ employees

It looks pretty stable to me.

View full review »
CC
DevSecOps at a financial services firm with 10,001+ employees

The stability is very good. It probably needs to be improved a bit more. The cluster technology is first-generation and is still maturing. It needs to mature a bit more.

IQ is quite stable. It's a very simple engine, it takes something in, makes a decision, and then gives you the output.

View full review »
ES
Security Consultant at a financial services firm with 1,001-5,000 employees

It is a quite stable solution. I would rate the stability as a seven out of ten.

View full review »
RS
Senior Architect at a insurance company with 1,001-5,000 employees

We've only had the server go down one time in about two years, so that's good.

View full review »
BS
Enterprise Application Security Analyst at a comms service provider with 5,001-10,000 employees

The stability is good. There have been no problems that I'm aware of.

View full review »
AC
Product Strategy Group Director at Civica

It's a stable product, especially compared to some of its competitors.

View full review »
LR
Section Chief at a government with 201-500 employees

Sonatype Nexus Lifecycle is a very stable tool; my team hasn't had any issues with it. My company had a significant outage two or three weeks ago, so all storage was lost. Still, in just a short while, Sonatype Nexus Lifecycle was up again, which makes Sonatype Nexus Lifecycle a very good tool.

View full review »
EK
Security Team Lead at Tyro Payments Ltd

The stability has been pretty good. We're pretty happy with it. There have been no issues there.

View full review »
SL
Solutions Delivery Lead at a financial services firm with 201-500 employees

I haven't had any issues with it crashing. It is very stable. However, when we use it in real-time builds (or very frequent builds), there is sometimes a bit of lag between getting results back by 10 to 30 seconds. Other than that, we haven't had any issues.

View full review »
SH
DevOps Engineer at Guardhat

Overall, the stability is pretty good. I haven't figured this out yet, but occasionally we do see failures in the Jenkins build. I haven't figured out why yet. I don't know if it's an issue with our Jenkins server or if it's with Sonatype. But otherwise, it seems pretty stable.

View full review »
MK
Systems Analyst at Thrivent Financial for Lutherans

The stability is great.

View full review »
MI
Technical Consultant at a computer software company with 10,001+ employees

I would rate the stability of Sonatype Nexus Lifecycle a seven out of ten.

View full review »
MA
Computer Architecture Specialist at a energy/utilities company with 10,001+ employees

It's very stable. I don't recall ever seeing problems. The main concern would be data-disk corruption, but I haven't seen it, even though the server, due to patching, has been rebooted multiple times.

View full review »
AM
Java Development Manager at a government with 10,001+ employees

It is stable as of now, the version we are using. We hope that it continues to work as we expect.

View full review »
FT
IT Security Manager at a insurance company with 5,001-10,000 employees

I think we have had zero downtime since I have been here. I didn't hear that there ever was an issue before, so it's been absolutely great.

Part of the deployment and maintenance is done by me. Upgrading the solution to a new level has only been done by one single person in the past, who spent three to four hours per upgrade on it. It's really low maintenance for us.

View full review »
Hisham Shoukathali - PeerSpot reviewer
Automation Technical Lead at a tech vendor with 10,001+ employees

Sonatype Nexus Lifecycle is a stable solution.

View full review »
Axel Niering - PeerSpot reviewer
Software Architect Sales Systems at SV Informatik GmbH

Nexus Lifecycle has had no problems until now. There is just a small circle of people using it directly, so this is not a critical mass of users. I cannot say what the stability will be like when there are more people using it. But right now, there is absolutely no problem. It just works.

The users in our company are developers and software architects.

View full review »
RH
Application Development Manager at a financial services firm with 501-1,000 employees

It is stable.

Users of the solution include our security officer, our application architect, and me. I manage all of the development and the developers who work on upgrading libraries.

Not many people are needed to maintain this solution. We need two or three people. One person is from our service support where the Sonatype Server is deployed and managed. Another person is the application architect who reviews the libraries.

View full review »
RC
Security Analyst at a computer software company with 51-200 employees

I've never had any stability issues with the application. I haven't performed any of the upgrades, but we've never had any downtime and we've never had any issues with notifications or an inability to access the information we need.

View full review »
RN
Technical Manager at a financial services firm with 1,001-5,000 employees

Nexus Lifecycle is stable. 

View full review »
JC
DevOps Engineer at a tech vendor with 51-200 employees

Nexus 3 is not yet stable enough. IQ is perfectly stable. We have not had any stability issues with it.

View full review »
Buyer's Guide
Sonatype Lifecycle
March 2024
Learn what your peers think about Sonatype Lifecycle. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,578 professionals have used our research since 2012.