“Since implementing [Nexus Lifecycle], we have not had a delay in a release due to unknown security issues that we found near the end of our version release cycle.”
"In addition to Nexus Pro's procurement capabilities, we especially liked that the artefact database is just a file system. This makes backing up of the artifacts very easy, makes recovery from various problems easier, and allows access to the database in other ways beside via the repository manager as well."
"Everyone who saw Nexus Lifecycle said, ‘This is something we can work with. This is the tool that works for us."
“Previously, we used open source tools, but had problems with a lot of false positives which were not well-accepted by our developers. With the Nexus solution, we have practically no false positives.”
“If you design secure software, use a secure process accreditation should be done by the time the code is complete.”
“Open source governance has to work with developers and security practitioners alike — not against them. With Sonatype, we've eliminated thousands of hours of manual processes and created automated controls that have improved productivity and reduced risk across the board.”
“We have teams that go from concept to deployment in less than 24 hours, and that frequent incremental delivery of business value makes us incredibly productive.”
“It was not easy to find a solution that covered all of our complex legal and security requirements. After evaluating a dozen different tools, we chose Sonatype Lifecycle for its completeness of pulling copyright and licensing information, data accuracy, and quick identification of legal, security, and technical findings.”
“Sonatype's renowned data quality proved to be precisely what they needed to significantly enhance the accuracy of their security violations.”