57 Sonatype Testimonials

Industry
Company Size
15 per page
  • 15
Reset
  • "We narrowed down our trials to Sonatype Nexus and JFrog Artifactory. We decided to go with Nexus because the OSS version seemed to deliver most of what we were looking for."

  • "Before Lifecycle, we really had no way to monitor policy violations or licensing risks. Lifecycle gave us a way to actually prioritize what to fix."

  • "In addition to Nexus Pro's procurement capabilities, we especially liked that the artefact database is just a file system. This makes backing up of the artifacts very easy, makes recovery from various problems easier, and allows access to the database in other ways beside via the repository manager as well."

  • “Since implementing [Nexus Lifecycle], we have not had a delay in a release due to unknown security issues that we found near the end of our version release cycle.”

  • “If you design secure software, use a secure process accreditation should be done by the time the code is complete.”

  • “Open source governance has to work with developers and security practitioners alike — not against them. With Sonatype, we've eliminated thousands of hours of manual processes and created automated controls that have improved productivity and reduced risk across the board.”

  • “We have teams that go from concept to deployment in less than 24 hours, and that frequent incremental delivery of business value makes us incredibly productive.”

  • “It was not easy to find a solution that covered all of our complex legal and security requirements. After evaluating a dozen different tools, we chose Sonatype Lifecycle for its completeness of pulling copyright and licensing information, data accuracy, and quick identification of legal, security, and technical findings.”

  • “Sonatype's renowned data quality proved to be precisely what they needed to significantly enhance the accuracy of their security violations.”