A malicious release of TensorLake's TypeScript SDK, tensorlake@0.5.144, used an install hook to search for developer credentials and accept remote commands. Sonatype's code review found that its ...
Milestone: Since Sonatype began tracking malicious open source packages in 2017, we have logged nearly 2 million malicious packages. Scale: Sonatype Research Labs logged 149,329 open source malware ...
Secure open source consumption requires more than an approved package registry or a scan before release. Teams need to control where components come from, evaluate ...
The time required to write code is shrinking. The work required to validate code for production is not. AI coding assistants and agents can compress implementation work from days to hours. But ...
Sonatype is proud to be recognized as a Leader in The Forrester Wave™: SCA Software 2024. Forrester evaluated 10 top providers and named Sonatype a Leader among them. To us, this underscores our ...
Report security issues for a potential reward. Rewards are based on the severity of the finding and its impact on the organization. Let’s work together to help secure Sonatype’s products and services ...
With over 100,000 deployments globally, Nexus Repository received the highest rating among leaders. See why enterprises choose Sonatype Nexus Repository.
This Acceptable Use Policy (this “Policy”)applies to your use of all Services offered by Sonatype. The examples described in this Policy are not exhaustive. We may modify this Policy at any time by ...
To better secure your software supply chains, start by getting a clear understanding of the threat landscape — particularly the difference between malware and vulnerabilities. Misinterpreting these ...
That speed can improve developer productivity. But it can also increase the volume of unsafe software entering development workflows. In Q2 2026 alone, Sonatype observed 464,650 new malicious packages ...
As open source software continues to fortify modern applications, attackers are finding new and increasingly efficient ways to exploit the trust developers place in public ecosystems. Sonatype ...
In the modern shifting landscape of software supply chain attacks, prioritizing application security and integrity is non-negotiable. As heavy reliance on open source software components grows, the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results