I think that the speed of updates of vulnerabilities in Sonatype Repository Firewall could be improved because now with artificial intelligence, the detection of past or new vulnerabilities is a matter of hours and so is the exploitation. If the information is not pushed immediately by Sonatype in the repositories, we risk missing the vulnerability. The updates should now be pretty instant, and they should somehow have a way of pushing those updates immediately. We do not use automatic threat detection features in Sonatype Repository Firewall in the sense of automatic fixing. It's not in place. We need to bump up our dependencies manually, and I'm not sure if the IT department has something in place for dependencies like Tomcat, but I don't know about it. I don't know how I would assess the real-time monitoring feature in Sonatype Repository Firewall; I have no opinion on that.
For Sonatype, there is a feature for waiving a vulnerable component that cannot be fixed due to limitations. However, I wish Sonatype would improve notifications regarding waivers, so the security team knows to look into it instead of relying on user emails or checking ourselves. I think the price for the product is on the high side, as some components are very expensive, such as Sonatype Repository Firewall. It is not a cheap product, but security can come at a cost. Time definitely is saved because security is a requirement, and it provides great value, although everyone likes things to be cheaper. But at the end of the day, you pay for what you have to.
I recommend integrating artificial intelligence capabilities into Sonatype Repository Firewall for real-time intelligence updates regarding security risks. I also suggest enhancing policy control for improved granular policy settings and better integration with DevOps pipelines, especially in container-based workflows. I find the documentation very good as I often refer to it for information. The user interface is also very good, but I have noticed some false positives where safe components get blocked, causing unnecessary delays for developers.
There are several features lacking in the current offering, particularly concerning container support and AI packages, like humming phase support. However, I have heard that it is on the roadmap for 2025.
I suggest that Sonatype should add support for more computer languages. The product works well with languages such as Java and C#, but in my opinion, adding support for more languages would be really good. In addition, I believe that they should add some more functionality to improve the quality of the code.
Sonatype Repository Firewall ensures secure software supply chains by inspecting open-source components for vulnerabilities and other threats at the point of ingress.
Designed for real-time protection, Sonatype Repository Firewall not only identifies but also controls potentially malicious, vulnerable, or non-compliant components before they reach development teams and CI/CD pipelines. It offers automation for quarantine, blocking workflows, and integrates with repository managers like...
I think that the speed of updates of vulnerabilities in Sonatype Repository Firewall could be improved because now with artificial intelligence, the detection of past or new vulnerabilities is a matter of hours and so is the exploitation. If the information is not pushed immediately by Sonatype in the repositories, we risk missing the vulnerability. The updates should now be pretty instant, and they should somehow have a way of pushing those updates immediately. We do not use automatic threat detection features in Sonatype Repository Firewall in the sense of automatic fixing. It's not in place. We need to bump up our dependencies manually, and I'm not sure if the IT department has something in place for dependencies like Tomcat, but I don't know about it. I don't know how I would assess the real-time monitoring feature in Sonatype Repository Firewall; I have no opinion on that.
For Sonatype, there is a feature for waiving a vulnerable component that cannot be fixed due to limitations. However, I wish Sonatype would improve notifications regarding waivers, so the security team knows to look into it instead of relying on user emails or checking ourselves. I think the price for the product is on the high side, as some components are very expensive, such as Sonatype Repository Firewall. It is not a cheap product, but security can come at a cost. Time definitely is saved because security is a requirement, and it provides great value, although everyone likes things to be cheaper. But at the end of the day, you pay for what you have to.
I recommend integrating artificial intelligence capabilities into Sonatype Repository Firewall for real-time intelligence updates regarding security risks. I also suggest enhancing policy control for improved granular policy settings and better integration with DevOps pipelines, especially in container-based workflows. I find the documentation very good as I often refer to it for information. The user interface is also very good, but I have noticed some false positives where safe components get blocked, causing unnecessary delays for developers.
There are several features lacking in the current offering, particularly concerning container support and AI packages, like humming phase support. However, I have heard that it is on the roadmap for 2025.
The tool needs to improve its file systems. The product should also include zero test feature.
I suggest that Sonatype should add support for more computer languages. The product works well with languages such as Java and C#, but in my opinion, adding support for more languages would be really good. In addition, I believe that they should add some more functionality to improve the quality of the code.