Over a million developers have joined DZone.

Nexus Repository Rising: Say Hello to the New Pro

DZone's Guide to

Nexus Repository Rising: Say Hello to the New Pro

Sonatype is expanding component support in Nexus Repository OSS. Nexus Repository now offers free support for seven components types.

· DevOps Zone ·
Free Resource

Learn how integrating security into DevOps to deliver "DevSecOps" requires changing mindsets, processes and technology.

Free Birds, Free Coffee, and Free Willy

Sonatype is expanding component support in Nexus Repository OSS to include PyPI and RubyGems packages. Nexus Repository now offers free support for seven components types. 

Screen_Shot_2016-09-08_at_1.51.33_PM.pngBook Smart, Street Smart

Four years ago, we introduced software composition analysis within our repository. Why? Developers using components to build software want to know if those parts are good or bad. Licenses, security vulnerabilities, versions, age, and adoption rates are all attributes of good and bad. While a basic version of component analysis is available in Nexus Repository OSS, more advanced capabilities of Repository Health Check (RHC) are available in Nexus Repository Pro.

Image title

Development teams don’t want to build software using bad parts. Every day, Sonatype analyzes millions of components across 70,000 repositories for organizations wanting to discriminate between good parts and bad parts. To achieve this, Sonatype combined machine learning algorithms (book smart) with a team of world-class experts who perform non-stop research to precisely distinguish good components from bad (street smart). As you can see, from RHC’s origins in 2012, we’ve all come a long way to help development teams get smarter about the parts they are using.

Nexus Repository Pro: Application Analysis

Repository Health Check helps development teams understand if defective, known vulnerable, or poor quality components live in their Nexus repositories. What RHC does not tell you is if those components have been used in an application. With the upcoming release of Nexus Repository 3.1, we have now integrated the ability to perform a detailed analysis of the components and applications within the repository. Application Health Check (AHC) will enable Nexus Repository users to quickly evaluate components used in the applications. AHC will provide details on known security vulnerabilities, open source license types, component age, download popularity, safer alternative versions available to developers, and more. 

This fall, we are introducing active-active high availability in Nexus Repository Pro. When development efforts are non-stop, Nexus Repository must be non-stop. High availability is built-in to Nexus Repository Pro and it is simple to configure, manage and maintain.

Learn how enterprises are using tools to automate security in their DevOps toolchain with these DevSecOps Reference Architectures.

devops ,sonatype ,nexus repository ,health checks

Published at DZone with permission of

Opinions expressed by DZone contributors are their own.

{{ parent.title || parent.header.title}}

{{ parent.tldr }}

{{ parent.urlSource.name }}