CARVIEW |
Manage SDLC Security Risk in the Tools You Already Use
Sonatype's software development lifecycle security solutions have you covered with 50+ supported languages, packages, and integrations across leading IDEs, source repositories, CI pipelines, DevSecOps tools, and ticketing systems.
Filters

Amazon Web Services
Manage and secure open source and third-party components in the cloud with Sonatype Nexus Repository and IQ Server.

Atlassian Bamboo
Shift application security and quality practices left by automatically sending alerts or failing Bamboo builds when application components are out of compliance with your open source policies.

Atlassian Bitbucket
Sonatype Lifecycle pushes component intelligence into Bitbucket where developers can view and remediate SDLC security policy violations with detailed Code Insights.

Azure DevOps
Shift security and quality practices left by automatically sending alerts or failing Azure builds when application components are out of compliance with your open source policies.

Chrome Extension
Identify the open source risk within a package before you even download it with our Chrome extension.

Eclipse
Empower developers with precise component and open source risk intelligence directly within the Eclipse IDE.

GitHub
Sonatype Lifecycle pushes component intelligence into GitHub where developers can view and respond to policy violations directly in pull requests.

GitLab
Our new Lifecycle integration with GitLab Ultimate lets you view vulnerability findings directly in your project’s Vulnerability Report and Dependency List.

Gradle
Resolve dependencies and deploy your artifacts and build information to Sonatype Nexus Repository.

IntelliJ IDEA
Empower developers with precise component intelligence directly within IntelliJ IDEA.

Jenkins
Shift security and quality practices left by automatically sending alerts or failing Jenkins builds when application components are out of compliance with your SDLC security policies.

JIRA
Auto-create Jira tickets when policy violations are triggered in Sonatype Lifecycle.
Package Support
Package |
![]() |
![]() |
![]() ![]() |
![]() |
---|---|---|---|---|
|
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
via Community |
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
|
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|
![]() |
|
|
|
|