Sonatype: Software Supply Chain Security (Private Cloud)
Reporting has improved vulnerability awareness but update speed still needs critical progress
What is our primary use case?
I wouldn't know about the challenges or difficulties with implementing Sonatype Repository Firewall because it is managed by the IT department, so I really don't know. I just use it with the CI/CD.
Sonatype Repository Firewall's best features include timely reporting of vulnerable dependencies in the software we write, which is one reason why my organization chooses it.
Sonatype Repository Firewall has helped my team identify vulnerabilities in open-source components by providing us reports, and we look at the reports to know that we have something to update.
What is most valuable?
I don't see how many people were involved in the process of implementation for Sonatype Repository Firewall because it's really another department, and I have no clue about the effort.
If I am asked to give a rating of Sonatype Repository Firewall from 1 to 10, where 10 is the best, I would rate it 7.5 or 8.
What needs improvement?
I think that the speed of updates of vulnerabilities in Sonatype Repository Firewall could be improved because now with artificial intelligence, the detection of past or new vulnerabilities is a matter of hours and so is the exploitation. If the information is not pushed immediately by Sonatype in the repositories, we risk missing the vulnerability. The updates should now be pretty instant, and they should somehow have a way of pushing those updates immediately.
We do not use automatic threat detection features in Sonatype Repository Firewall in the sense of automatic fixing. It's not in place. We need to bump up our dependencies manually, and I'm not sure if the IT department has something in place for dependencies like Tomcat, but I don't know about it.
I don't know how I would assess the real-time monitoring feature in Sonatype Repository Firewall; I have no opinion on that.
For how long have I used the solution?
I have been working with Sonatype Repository Firewall for a few years, specifically three years.
How are customer service and support?
I don't know about the technical support of Sonatype Repository Firewall because that's the job of the IT department, and I have no clue. I have never interacted with their support.
What about the implementation team?
Regarding the purchase of Sonatype Repository Firewall, the IT department knows how we purchased it, and they usually sign contracts with resellers, but I have no details about it.
What's my experience with pricing, setup cost, and licensing?
From the figure I see that is charged back to us for Sonatype Repository Firewall, I think it is quite high, and the IT department is putting in place an alternative open-source solution so that we do not have to pay 200 euros per developer per year, which is a lot considering we have thousands of developers. It's millions of euros or hundreds of thousands of euros that we would save, so in creating a project, we probably go to the open-source solution.
Which other solutions did I evaluate?
I see less and less benefit from using Sonatype Repository Firewall despite its elevated cost because with artificial intelligence built into our development environments like Kiro, for example, we can detect vulnerabilities in other ways, in a cheaper way, and not even waiting for the pipeline to run. Each developer can ask Kiro, 'Can you tell me if there is a vulnerability?' and it will tell you about it, so it's losing its importance.
What other advice do I have?
I would rate Sonatype Repository Firewall 7.5 out of 10.
Centralized repositories have strengthened our library security and support proactive vulnerability checks
What is our primary use case?
The major use case for Nexus Repository is for open source libraries and third-party libraries scanning. It will give you the vulnerabilities and security vulnerabilities of these third-party libraries. This is how we use it.
What is most valuable?
The biggest advantage of Sonatype is that you get an idea about the open source or third-party libraries vulnerabilities, including if there are any fixes for them and if it is utilized in our environment. Because there are many types of vulnerabilities, they call it composition, and it just gives you an idea of the security posture of your used libraries, third-party libraries, and open source components. Imagine if it was not there; how would you find out what is happening? That is because it is really significant. You get the vulnerability and what it is doing. Recently, we acquired Sonatype Repository Firewall, so you can block things and allow things, which is very useful for security.
The Health Check feature for repositories is for identifying vulnerabilities. Identifying vulnerabilities normally comes from the tool itself. It will mark something as vulnerable.
What needs improvement?
For Sonatype, they have a feature for waiving. Suppose you have something vulnerable, and this component cannot be fixed due to some other limitations. The severity of the vulnerabilities varies based on where it is, such as Internet-facing or air-gapped, and that affects the severity. If you have other controls and other measures, there is this feature in Sonatype, which is a great feature, where if the developer or user believes this is a false positive, or if they believe that this vulnerability can be fixed in a month or two due to restrictions and other compensating controls, this feature is amazing. However, I wish Sonatype would allow notifications. It gets stored in the system without notifications, so if Sonatype works on notifying us, the security team, that there is a waiver there and to look into it, that would be great because otherwise, we need to rely on users to tell us via emails, or we check ourselves, which requires reminders. The other thing is that sometimes you can waive it for one month, two months, or whatever when we agree on this. If Sonatype invests in reminders about when this waiver will be ending for the user and for us, that would be great.
I am not aware if Nexus Repository is scalable, as I have not participated in this. However, it serves our purpose.
For how long have I used the solution?
I started using Sonatype Nexus Repository before 2023, possibly in 2022 or 2019, but I do not have the exact dates because I was not involved in that process when they brought it in.
What do I think about the stability of the solution?
Nexus Repository is reliable, without a doubt.
How are customer service and support?
My impression of Sonatype's customer support and technical service is positive.
I would rate Sonatype's support a nine on a scale from zero to ten.
Which solution did I use previously and why did I switch?
I have not worked with any other competitors for the same use case, so I cannot really say something here. I cannot compare it at this time, but I know they are one of the top ones in the market.
How was the initial setup?
Sonatype's installation process and deployment procedure is interesting because we have people who purchased it. There are many features that are not security-related. There are policy administrators or security administrators, that is us, but there is another team doing all of that. I am not sure how complex it is, but I know they stay after hours to do that. I did not participate in something like that to tell, but I understand the complexity involved.
What about the implementation team?
We are customers of Sonatype. We get the product, we use the product, and we buy the product.
What was our ROI?
Buying Sonatype is eventually worth it because time definitely has great value, and security is a requirement as well. Generally, everyone prefers cheaper options. However, at the end of the day, you are going to pay for what you have to.
What's my experience with pricing, setup cost, and licensing?
The price for the Sonatype product is on the high side. From what I heard, some components such as Sonatype Repository Firewall are very expensive. However, security can be an expensive thing. It is not cheap. This is not a cheap tool.
What other advice do I have?
Hosting, proxying, and grouping repositories have a major benefit for any organization because it centralizes the information. Now you know what you have and what you do not have. You also have control over it, and you know the security posture of it. This helps you maintain a secure environment.
Sonatype helps with development environments because there are use cases for when someone needs one of these frameworks. You connect with the third-party libraries, and then we can have these libraries stored here. Not just stored, we also know the health of it and how it is doing. Sometimes, we have zero attacks with that through live checks, and we get that feedback.
Health checks contribute to our identification procedure by checking if that is really a vulnerability or not. For example, if we have a vulnerability in that library, it does not necessarily mean the whole library is vulnerable because of one function. This library is used in the code that we have, but that specific vulnerable function is not present. In that scenario, we check if it applies to what we have or not.
For assessing lifecycle management integration with CI/CD pipelines, there are other tools we use. We have Fortify integrated into the pipeline. When you run the pipeline, part of it is the scanning. When you run that, you get the vulnerabilities and the issues that you have in this pipeline.
I would rate this product a nine overall.
Centralized repositories have strengthened open-source security and improved vulnerability insight
What is our primary use case?
The major use case for Sonatype Repository is for open-source libraries, third-party libraries, and scanning. It gives you the vulnerabilities and security vulnerabilities of these third-party libraries.
In terms of lifecycle management and integration with CI/CD pipelines, we assess the pipelines with Fortify integrated into part of the pipeline. When you run the pipeline, part of it is the scanning, and you get the vulnerabilities and the issues in this pipeline.
What is most valuable?
The biggest advantage of Sonatype is that you get an idea about the open source or third-party libraries vulnerabilities. You know if there are any fixes for them and if it is utilized in our environment. It gives you an idea of the security posture of your used libraries, third-party libraries, and open source components. It also shows you the vulnerabilities and what is being done. Recently, we acquired Sonatype Repository Firewall, which is very useful for security because you can block things and allow things.
The Health Check feature for repositories is for identifying vulnerabilities, basically. It normally marks something as vulnerable, but it also checks if it is accepted or not.
Health checks contribute to my identification procedure because if we have a vulnerability, some vulnerabilities are in that library, but it does not necessarily mean that the whole library is vulnerable because of one function that might not be in our code. So I check if that is really a vulnerability or not.
The ability of Sonatype to manage NPM, Docker, and Maven helps us with development environments because if someone needs one of these frameworks, we can connect with third-party libraries and have them stored here. We also know the health of it and sometimes receive live checks and feedback.
Hosting, proxying, and grouping repositories have a major benefit by being centralized for our organization. You know what you have and what you do not, and maintain a secure environment, knowing its security posture.
What needs improvement?
For Sonatype, there is a feature for waiving a vulnerable component that cannot be fixed due to limitations. However, I wish Sonatype would improve notifications regarding waivers, so the security team knows to look into it instead of relying on user emails or checking ourselves.
I think the price for the product is on the high side, as some components are very expensive, such as Sonatype Repository Firewall. It is not a cheap product, but security can come at a cost.
Time definitely is saved because security is a requirement, and it provides great value, although everyone likes things to be cheaper. But at the end of the day, you pay for what you have to.
For how long have I used the solution?
I started using this product before 2023, possibly in 2022 or 2019, but I do not have the exact dates because I was not involved in that process when they brought it in.
What do I think about the stability of the solution?
Sonatype Repository is reliable and stable.
How are customer service and support?
My impression of customer support and technical service from Sonatype is positive.
I would give them a nine for support on a scale from zero to ten.
How was the initial setup?
The installation process and deployment procedure for Sonatype is complex because the administration team handles that, and I know they stay after hours to do it, but I did not participate to know the details.
What about the implementation team?
We are customers of Sonatype; we get the product, we use it, and we buy it.
Which other solutions did I evaluate?
I have not worked with any competitors yet, so I cannot compare Sonatype to anything right now, but I know they are one of the top ones in the market.
What other advice do I have?
Sonatype is pretty much a leader and stands out in their field.
We have it on-premises; all is on-prem because sometimes the offerings of the cloud are not here in our country. The cloud area is still evolving, and we are not cloud-based yet.
Automated policy checks have protected builds and now prevent vulnerable dependencies in real time
What is our primary use case?
My main use case for Sonatype Repository Firewall is to check dependencies for vulnerabilities, block any download content that poses a risk, and enforce and adhere to security policies in real-time. I check for any suspicious activity and prevent vulnerable and malicious code from entering the build. When application teams create images, I check for vulnerabilities, block critical and vulnerable-level content, and block packages if someone tries to download unauthorized images or engages in suspicious activities using vulnerability intelligence.
An example would be when a developer is building a Java-based application with Maven. As they write code and add dependencies, the build tool requests a package from Sonatype Repository Firewall, which is integrated with the proxy repository that connects to the internet to download packages. During this process, whenever a request goes to the Nexus repository, Sonatype Repository Firewall checks the component before downloading it. If any vulnerability is detected, such as one related to Log4j, the policies applied at the firewall level help block the component containing critical severity vulnerabilities. The actions taken include blocking the download, putting the component into quarantine, and informing the developer that it was locked due to a critical vulnerability.
What is most valuable?
Sonatype Repository Firewall immediately identifies vulnerable content and helps block it promptly. It stops bad components before they ever enter my environment and helps developers choose correct and safer versions. It detects problems early rather than after accidents happen, and applies automatic enforcement of policies. This protects against threats and helps reduce human errors.
The automatic enforcement happens at different stages. For instance, if an application team requests any dependency to the Nexus Sonatype repository proxy, it first goes to the firewall, which intercepts it before downloading and checks for vulnerabilities, malware signals, and policy rules. If safe, it allows the dependency to be downloaded. If anything risky is found, it blocks it instantly without human intervention. Once a component is downloaded, it gets stored in the cache, allowing faster downloads in the future since the component is already available in the local repository.
Since I started using Sonatype Repository Firewall more than five years ago, it has had a positive impact on security and development speed. It helps prevent security incidents, fixes vulnerabilities early, and enables stable releases for applications. It speeds up development with safer dependencies by eliminating manual security checks and helps reduce human error and knowledge gaps, standardizing my DevOps pipeline and framework according to security guidelines.
What needs improvement?
I recommend integrating artificial intelligence capabilities into Sonatype Repository Firewall for real-time intelligence updates regarding security risks. I also suggest enhancing policy control for improved granular policy settings and better integration with DevOps pipelines, especially in container-based workflows.
I find the documentation very good as I often refer to it for information. The user interface is also very good, but I have noticed some false positives where safe components get blocked, causing unnecessary delays for developers.
For how long have I used the solution?
I have been using Sonatype Repository Firewall for over three years.
What do I think about the stability of the solution?
Sonatype Repository Firewall is stable, and although I explored alternatives like JFrog Artifactory and JFrog X-ray, I did not find them as valuable for my organization.
What do I think about the scalability of the solution?
My product runs on a container-based platform on AWS, utilizing auto-scaling to handle distributed traffic. The policies are enforced in a stateless manner and shared across the system, which helps manage load on the primary nodes effectively during high traffic.
How are customer service and support?
My experience with customer support has been minimal since I have not faced significant issues, and any past support requests during migration were handled well.
Which other solutions did I evaluate?
Sonatype Repository Firewall is stable, and although I explored alternatives like JFrog Artifactory and JFrog X-ray, I did not find them as valuable for my organization.
What other advice do I have?
I advise others considering Sonatype Repository Firewall to ensure they have strong organization-wide policies that comply with security regulations. This product can handle large volumes of data and scale as needed, offering excellent scalability and security features. It is a good product, and I encourage others to use it for large-scale applications if they wish to implement it. I have rated this product 9 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Accurate database support blocks malicious code with excellent support
What is our primary use case?
Many companies, including ours, use Nexus Repository due to concerns about malware and critical vulnerabilities. There should be a specific method to prevent malicious packages from entering the internal network, so our company uses Nexus Repository. We usually consider adding the firewall feature on top of the Repository, with the main purpose being to block malicious packages.
What is most valuable?
The firewall is the only solution that supports Nexus Repository. This firewall comes with an accurate database, which can identify most malicious code from entering. It relies on the Sonatype accurate database, so the accuracy is excellent. There is no other option except Sonatype deploy to the firewall.
What needs improvement?
There are several features lacking in the current offering, particularly concerning container support and AI packages, like humming phase support. However, I have heard that it is on the roadmap for 2025.
For how long have I used the solution?
I have been using this solution for four years.
What do I think about the stability of the solution?
It is software, so there is always a possibility of bugs, however, they are quite fast in fixing these bugs. It is quite stable.
What do I think about the scalability of the solution?
There is an option to scale the capacity using an external database, and then you also have support. I do not think there is any issue with scalability.
How are customer service and support?
The customer service is fantastic. They provide the required responses and relevant support, which is the biggest advantage of using Sonatype.
Which solution did I use previously and why did I switch?
I do not have handling experience with another firewall. Sonatype Firewall is the only one I have been using. There is only one other alternative.
How was the initial setup?
The initial setup is quite straightforward and easy. It is not complicated.
What about the implementation team?
Just a couple of staff members can complete the installation and configuration.
What's my experience with pricing, setup cost, and licensing?
Also, I consider it average. Some people might consider it expensive, however, since it supports many beautiful features, I would say it is worth it.
Which other solutions did I evaluate?
We looked at Sonatype or Gather. There are not that many options.
What other advice do I have?
I would give the solution eight out of ten. I would look at the comparison of Sonatype to some other firewalls. There is room for improvement, especially mentioning container support and AI packages.