惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
O
OpenAI News
TaoSecurity Blog
TaoSecurity Blog
Cloudbric
Cloudbric
Know Your Adversary
Know Your Adversary
I
Intezer
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Tenable Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
P
Privacy & Cybersecurity Law Blog
T
Threatpost
AWS News Blog
AWS News Blog
Google Online Security Blog
Google Online Security Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
aimingoo的专栏
aimingoo的专栏
Cyberwarzone
Cyberwarzone
GbyAI
GbyAI
P
Proofpoint News Feed
S
Security @ Cisco Blogs
D
Docker
爱范儿
爱范儿
Hugging Face - Blog
Hugging Face - Blog
Help Net Security
Help Net Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Tor Project blog
博客园 - 【当耐特】
月光博客
月光博客
罗磊的独立博客
G
Google Developers Blog
M
MIT News - Artificial intelligence
小众软件
小众软件
C
Check Point Blog
P
Proofpoint News Feed
H
Heimdal Security Blog
云风的 BLOG
云风的 BLOG
H
Hackread – Cybersecurity News, Data Breaches, AI and More
W
WeLiveSecurity
PCI Perspectives
PCI Perspectives
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
Security Affairs
Attack and Defense Labs
Attack and Defense Labs
S
Schneier on Security
H
Hacker News: Front Page
The Last Watchdog
The Last Watchdog
H
Help Net Security
T
Threat Research - Cisco Blogs
阮一峰的网络日志
阮一峰的网络日志
Hacker News: Ask HN
Hacker News: Ask HN
Project Zero
Project Zero

2024 Sonatype Blog

The Hugging Face Incident Changes the Vulnerability Equation What Is Grounding? Why AI Coding Assistants Need Better Intelligence Open Source, Open Infrastructure, and the Space Between Request for Comments: CARE and Maven Central Q2 2026 Open Source Malware Index AI Is Forcing a New Open Source Security Model Vulnerability Prioritization Is Missing the AI-Era Point The Hidden National Security Threat Inside AI-Driven Software Miasma Returns: Leo Platform Compromise in npm The Rise of Collective Defense for Open Source Signal Over Noise: Reachability Analysis Is the Reality Check SCA Has Been Missing Software Security Has to Start at Assembly easy-day-js Targets Mastra, Dependency Attacks Grow Open Publishing, Commercial Scale Software Dependency Cooldowns Are a Symptom, Not a Strategy Atomic Arch npm Campaign Adds Malicious Dependency From SBOMs to AI BOMs: Why SPDX 3.0 Matters Mythos Found 10,000 Vulnerabilities. The Bigger Challenge Is Fixing Them New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages Lazarus Group's Latest: Brandjacking Campaign on npm 5 Steps to Turn Your RMF Backlog Into a Continuous ATO: The CSRMC Migration Playbook The AI Race Is Becoming a Remediation Race Red Hat Cloud Services npm Packages Hijacked Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies AI Is Making Software Autonomous, and Governance Must Follow Your Outdated Repository Still Works, But It May Not Be Safe Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT AppSec Tools Explained: SAST vs SCA vs DAST | Sonatype Managing Open Source Software Risks With the HeroDevs EOL Dashboard Shai-Hulud is Back: Maintainer Accounts Are Still the Soft Target Building Trusted AI Development With Kiro and Sonatype Guide How to Build a Software Supply Chain Security Playbook The Evolution of Open Source Malware: From Volume to Trust Abuse The Mythos AI Vulnerability Storm: What to Do Next Malicious PyTorch Lightning Packages Found on PyPI Why Developer Experience Is the Foundation of DevSecOps Success Open is Not Costless: Reclaiming Sustainable Infrastructure Q1 Updates in Nexus Repository: More Formats, Stronger Operations, and a Better Day-to-Day Experience Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths The Time Is Now to Prepare for CRA Enforcement Mythos and the AI Vulnerability Storm: Exploring the Control Point When AI Writes Code, Who Governs the Dependencies? Why Software Supply Chain Security Requires a New Playbook Q1 2026 Open Source Malware Index: Adaptive Attacks Exploit Trust Modernizing Nexus Repository: Moving Beyond OrientDB AI, DevSecOps, and the Future of Application Security: The Gartner® Report How Sonatype's Container Scanning Protects You From Zero-Days Axios Compromise on npm Introduces Hidden Malicious Package Is Your Repository Ready for What's Next? Autonomous Development and AI: Speed vs. Security Grounded Intelligence Ensures Safe AI Software Development Compromised litellm PyPI Package Delivers Multi-Stage Credential Stealer Golden Pull Requests: Automating Trusted Remediation Without Breaking Builds Sonatype Discovers Two Malicious npm Packages
Sonatype Innovate: Real Peer Connections, Real Product Influence, Real Recognition
2026-04-21 · via 2024 Sonatype Blog

Software supply chain security is maturing. The practitioners leading that charge deserve more than a customer portal.

DevSecOps teams that have gotten serious about software supply chain security share a common experience: at some point, the technical problem becomes an organizational one. The tooling works. The pipeline integrations are in place. But getting buy-in across engineering, security, legal, and leadership — and sustaining it — is a different challenge entirely.

It's also one that's rarely documented. Vendor documentation covers product capabilities. Analyst reports cover market trends. What's harder to find is practical guidance from practitioners who have already navigated adoption across multiple engineering organizations, aligned competing threat models between DevOps and security teams, or built the internal case for investment at the CISO level.

That gap is what Sonatype Innovate is designed to close.

What Is Innovate?

Sonatype Innovate is a customer advocacy program built for practitioners who are actively using Sonatype products in production. It's not a loyalty tier or a rebranded newsletter. It's a structured community where customers connect with each other, engage directly with Sonatype's product and engineering teams, and share what they've learned across the full DevSecOps spectrum — from Software Architecture and Engineering to Security, DevOps, and Legal.

Participation is built around four areas:

Direct product access. Innovators connect with Sonatype's Product Management, Customer Success, and Technical Support teams. Feedback from Innovate members has shaped platform development. If there's a capability gap creating friction in your workflow, this is the channel to surface it.

Peer-to-peer knowledge sharing. The program creates dedicated spaces for practitioners to discuss what's actually working — not polished case study versions, but the real operational details. Cross-functional collaboration is a core design element, given how often software supply chain security requires coordination across teams with different priorities.

Thought leadership and recognition. The Sonatype Elevate Awards, which recognize outstanding customer achievement in software supply chain security, draw directly from the Innovate community. The program also supports speaking opportunities and content creation for members who want to extend their profile beyond their own organization.

Professional development. Structured learning opportunities covering Sonatype products and supply chain security best practices — useful for teams still building internal depth.

Who It's Built For

Sonatype Innovate is open to Sonatype customers who are actively engaged with the platform. The program spans organizations across financial services, healthcare, technology, manufacturing, and government — and is designed for developers, architects, DevOps engineers, security practitioners, and engineering or security leaders.

You don't need a fully mature program to participate. You need real-world experience and a willingness to engage with peers who share the same challenges.

The time commitment is flexible. Members choose participation activities based on their schedule and interests. Public attribution is never required — the program includes options for anonymous knowledge-sharing and NDA-protected peer discussions.

Why Practitioner Communities Matter in This Discipline

Software supply chain security adoption often stalls not because the technology doesn't work, but because organizations can't find credible evidence that it works for organizations like theirs. CISOs want validated proof. Engineering leaders want operational examples, not theoretical frameworks.

Every practitioner who shares a real outcome, even without a public logo, moves that conversation forward across the industry. In a discipline where implementation friction remains the primary adoption barrier, and where the downstream consequences of getting security wrong range from breaches to compliance failures to supply chain incidents, that kind of peer-to-peer knowledge transfer has real impact.

Getting Started

If you're a Sonatype customer interested in connecting with peers and contributing to the direction of the platform, reach out to your Sonatype customer support representative or contact the program team directly at advocacy@sonatype.com.

Tags