通過Sonatype Platform瀏覽器擴展來達到“安全左移”——掃描開源倉庫以檢測已知漏洞。
Chromium瀏覽器的擴展與Sonatype Platform配合,賦予開發人員在軟件開發生命週期的早期做出更明智的選擇。
將這個擴展連接到您的公司裡的Sonatype Lifecycle服務器,並在瀏覽公共開源註冊表(如Java的Maven Central、JavaScript的NPM、Python的PyPi等等)時,即時獲取風險洞察。
這個擴展取代了我們之前的擴展(Nexus IQ Chrome擴展),該擴展將在2023年底之前停用。
Latest reviews
- (2023-08-16) Neil Schloth: A great tool for analyzing OSS components on the web for high-risk security vulnerabilities prior to downloading for use. Prevent mistakes early on in the SDLC by alerting on insecure packages before they are built in to application code.
- (2023-08-10) Roy Decker: An awesome solution for researching open source components that are being considered for an application.
- (2023-07-14) Ben Hartley: The ultimate in shifting left!
- (2023-07-14) Patrick Kiessling: Nice!
- (2023-07-14) Paul Meharg: I find this very useful to get a preview of the security and legal implications of acomponent before I start to write code! Keeps me from creating technical debt from the git-go.
- (2023-07-14) Adam Such: Very useful plugin!
- (2023-07-14) Alexander Plattel: Excellent tool for looking at Open Source packages before you download them.
- (2023-07-11) Joseph Bernie: An extremely useful plugin for Sonatype customers!!