sonatype Archives - Developer Tech News https://www.developer-tech.com/news/tag/sonatype/ Gaming, Apps, HTML5, Java, PHP, C#, .net, IOT Tue, 12 Sep 2023 13:22:25 +0000 en-GB hourly 1 https://www.developer-tech.com/wp-content/uploads/sites/3/2020/09/dev-icon-60x60.png sonatype Archives - Developer Tech News https://www.developer-tech.com/news/tag/sonatype/ 32 32 Sonatype reveals DevOps and SecOps leaders’ views on generative AI https://www.developer-tech.com/news/2023/sep/12/sonatype-reveals-devops-secops-leaders-views-generative-ai/ https://www.developer-tech.com/news/2023/sep/12/sonatype-reveals-devops-secops-leaders-views-generative-ai/#respond Tue, 12 Sep 2023 13:22:22 +0000 https://www.developer-tech.com/?p=45125 While the tech community remains divided on the potential of generative AI tools, there’s a consensus that their impact on the industry is comparable to the adoption of cloud technology. Software engineers are harnessing generative AI to explore libraries, create new code, and enhance their development process, while application security professionals employ it for code... Read more »

The post Sonatype reveals DevOps and SecOps leaders’ views on generative AI appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/sep/12/sonatype-reveals-devops-secops-leaders-views-generative-ai/feed/ 0
Malicious PyPI package discovered in ongoing ‘PaperPin’ campaign https://www.developer-tech.com/news/2023/aug/04/malicious-pypi-package-ongoing-paperpin-campaign/ https://www.developer-tech.com/news/2023/aug/04/malicious-pypi-package-ongoing-paperpin-campaign/#respond Fri, 04 Aug 2023 11:05:45 +0000 https://www.developer-tech.com/?p=44995 In a recent analysis conducted by Sonatype, a malicious Python Package Index (PyPI) package named ‘VMConnect’ was discovered masquerading as the legitimate VMware vSphere connector module ‘vConnector’. The counterfeit package was found to contain sinister code designed to compromise users’ systems. Further investigation revealed an ongoing campaign involving additional packages like “ethter” and “quantiumbase,” all... Read more »

The post Malicious PyPI package discovered in ongoing ‘PaperPin’ campaign appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/aug/04/malicious-pypi-package-ongoing-paperpin-campaign/feed/ 0
Sonatype uncovers further malicious PyPI and npm packages https://www.developer-tech.com/news/2023/jun/23/sonatype-uncovers-further-malicious-pypi-npm-packages/ https://www.developer-tech.com/news/2023/jun/23/sonatype-uncovers-further-malicious-pypi-npm-packages/#respond Fri, 23 Jun 2023 15:47:27 +0000 https://www.developer-tech.com/?p=44763 Sonatype continues to uncover a significant number of malicious packages within the PyPI and npm software registries. Among the flagged packages were several Python packages published on PyPI, masquerading as legitimate libraries named after the popular npm “colors” library. The malicious packages, including names such as “broke-rcl,” “brokescolors,” and “trexcolors,” exclusively targeted the Windows operating... Read more »

The post Sonatype uncovers further malicious PyPI and npm packages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/jun/23/sonatype-uncovers-further-malicious-pypi-npm-packages/feed/ 0
80% of Spring framework downloads are exploitable versions https://www.developer-tech.com/news/2022/apr/05/80-of-spring-downloads-are-exploitable-versions/ https://www.developer-tech.com/news/2022/apr/05/80-of-spring-downloads-are-exploitable-versions/#respond Tue, 05 Apr 2022 11:55:01 +0000 https://developer-tech.com/?p=42830 Data from Sonatype suggests that 80 percent of weekly Spring framework downloads are still exploitable versions. Spring is a mighty popular framework—often ranking in the top three most-used Java frameworks. That’s why the Java developer community was shaken when a vulnerability named Spring4Shell (CVE-2022-22965) was leaked by a security researcher ahead of an official CVE... Read more »

The post 80% of Spring framework downloads are exploitable versions appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2022/apr/05/80-of-spring-downloads-are-exploitable-versions/feed/ 0
Sonatype analysis reveals a 73 percent surge in open-source demand https://www.developer-tech.com/news/2021/sep/15/sonatype-analysis-reveals-73-percent-surge-open-source-demand/ https://www.developer-tech.com/news/2021/sep/15/sonatype-analysis-reveals-73-percent-surge-open-source-demand/#respond Wed, 15 Sep 2021 13:22:58 +0000 https://developer-tech.com/?p=40952 A report from Sonatype has revealed a 73 percent surge in the demand for open-source despite a year of high profile vulnerabilities. The growing use of open-source to keep up with the pace of modern development makes it a prime target for cybercriminals. We’ve seen this multiple times in practice over the past year with... Read more »

The post Sonatype analysis reveals a 73 percent surge in open-source demand appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2021/sep/15/sonatype-analysis-reveals-73-percent-surge-open-source-demand/feed/ 0
Sonatype Lift uses deep code analysis to suggest bug fixes https://www.developer-tech.com/news/2021/jun/17/sonatype-lift-uses-deep-code-analysis-to-suggest-bug-fixes/ https://www.developer-tech.com/news/2021/jun/17/sonatype-lift-uses-deep-code-analysis-to-suggest-bug-fixes/#respond Thu, 17 Jun 2021 15:21:21 +0000 https://developer-tech.com/?p=40449 Sonatype has launched a new deep code analysis platform called Lift which can detect a wide range of bug types. Lift detects bugs ranging from style issues to complex coding errors commonly found in first-party source code and third-party open source libraries. Research from Veracode last year found that open-source libraries cause security flaws in... Read more »

The post Sonatype Lift uses deep code analysis to suggest bug fixes appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2021/jun/17/sonatype-lift-uses-deep-code-analysis-to-suggest-bug-fixes/feed/ 0
Sonatype: COVID-19 causes 28% drop in UK software development https://www.developer-tech.com/news/2020/may/21/sonatype-covid-19-28-drop-uk-software-development/ https://www.developer-tech.com/news/2020/may/21/sonatype-covid-19-28-drop-uk-software-development/#respond Thu, 21 May 2020 13:00:49 +0000 https://developer-tech.com/?p=38342 New research from Sonatype suggests COVID-19 has caused a 28 percent drop in UK software development. COVID-19 has gripped countries around the world and grinded their economies to a halt. Britain’s furlough scheme – seeing the state pay 80% of people’s wages – has prevented the level of job losses seen in many countries, but... Read more »

The post Sonatype: COVID-19 causes 28% drop in UK software development appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2020/may/21/sonatype-covid-19-28-drop-uk-software-development/feed/ 0