Skip to main content

Sonatype Unveils Industry-First AI Software Composition Analysis (SCA) to Power AI-Driven Innovation

Sonatype®, the leader in software supply chain security, today announced end-to-end AI Software Composition Analysis (AI SCA) capabilities that enable enterprises to harness the full potential of AI. With its unparalleled expertise in open source governance, Sonatype now extends its trusted platform to protect, manage, and optimize AI/ML models across development and deployment. Sonatype is the first and only company providing an end-to-end AI SCA solution, ensuring that enterprises can adopt AI with the same level of safety and productivity as traditional open source.

Open source AI/ML adoption is soaring — over the last 12 months, Sonatype has identified more than 300,000 models within customer software supply chains. As organizations rush to integrate AI-powered software and agentic AI solutions, they face the same security, compliance, and governance challenges that once plagued open-source software adoption. To confidently manage open source AI/ML usage in software supply chains, Sonatype provides:

  • Proactive AI threat detection: Sonatype blocks intentionally malicious AI models from entering enterprise development environments.
  • Centralized AI model governance: With Nexus Repository’s Hugging Face proxy support, development teams can efficiently store, manage, and govern AI/ML models within existing DevOps workflows.
  • Automated AI policy management: Sonatype enables organizations to enforce security and compliance policies across AI model usage.
  • Unmatched AI observability and compliance: Sonatype provides full visibility into AI/ML model consumption, strengthening AI/ML security and defense strategies and streamlining first- and third-party software evaluation so enterprises can scale AI safely.

“No one knows open source like Sonatype, and AI is the next frontier. Just as we revolutionized open source security, we are now doing the same for AI,” said Mitchell Johnson, Chief Product Development Officer at Sonatype. “We are the first company to address the entire AI/ML supply chain — giving enterprises and developers the confidence to deliver AI-powered solutions without compromising security, compliance, or velocity. By integrating seamlessly into existing DevOps workflows, we ensure developers can innovate freely while staying secure.”

In The Forrester WaveTM: Software Composition Analysis (SCA) Software, Q4 2024 report, the Forrester analyst noted Sonatype’s forthcoming AI capabilities would “catapult Sonatype ahead on both software supply chain and generative AI (genAI) SCA” and awarded Sonatype the highest possible marks in several categories, including AI component analysis.

“It has never been easier for organizations to integrate open source AI models into software, but with open source AI consumption comes the same risk facing users of traditional open source. It is imperative that we, as an industry, secure their use now in order to prevent unmanageable security workloads in the future,” said Brian Fox, Co-founder and CTO at Sonatype. “We are proud to offer developers and security teams an end-to-end platform that provides the visibility and governance capabilities needed to use AI models safely, setting organizations up for easy and efficient long-term security.”

AI is transforming software development, but enterprises cannot afford to take shortcuts when it comes to security and compliance. Sonatype makes it possible for organizations to integrate AI models into their development workflows confidently — just as they do with open source components today.

For more information on how Sonatype enables AI-powered development at scale, visit https://www.sonatype.com/solutions/open-source-ai.

The post Sonatype Unveils Industry-First AI Software Composition Analysis (SCA) to Power AI-Driven Innovation appeared first on SD Times.



from SD Times https://ift.tt/wT1RBVU

Comments

Popular posts from this blog

Difference between Web Designer and Web Developer Neeraj Mishra The Crazy Programmer

Have you ever wondered about the distinctions between web developers’ and web designers’ duties and obligations? You’re not alone! Many people have trouble distinguishing between these two. Although they collaborate to publish new websites on the internet, web developers and web designers play very different roles. To put these job possibilities into perspective, consider the construction of a house. To create a vision for the house, including the visual components, the space planning and layout, the materials, and the overall appearance and sense of the space, you need an architect. That said, to translate an idea into a building, you need construction professionals to take those architectural drawings and put them into practice. Image Source In a similar vein, web development and design work together to create websites. Let’s examine the major responsibilities and distinctions between web developers and web designers. Let’s get going, shall we? What Does a Web Designer Do?...

A guide to data integration tools

CData Software is a leader in data access and connectivity solutions. It specializes in the development of data drivers and data access technologies for real-time access to online or on-premise applications, databases and web APIs. The company is focused on bringing data connectivity capabilities natively into tools organizations already use. It also features ETL/ELT solutions, enterprise connectors, and data visualization. Matillion ’s data transformation software empowers customers to extract data from a wide number of sources, load it into their chosen cloud data warehouse (CDW) and transform that data from its siloed source state, into analytics-ready insights – prepared for advanced analytics, machine learning, and artificial intelligence use cases. Only Matillion is purpose-built for Snowflake, Amazon Redshift, Google BigQuery, and Microsoft Azure, enabling businesses to achieve new levels of simplicity, speed, scale, and savings. Trusted by companies of all sizes to meet...

2022: The year of hybrid work

Remote work was once considered a luxury to many, but in 2020, it became a necessity for a large portion of the workforce, as the scary and unknown COVID-19 virus sickened and even took the lives of so many people around the world.  Some workers were able to thrive in a remote setting, while others felt isolated and struggled to keep up a balance between their work and home lives. Last year saw the availability of life-saving vaccines, so companies were able to start having the conversation about what to do next. Should they keep everyone remote? Should they go back to working in the office full time? Or should they do something in between? Enter hybrid work, which offers a mix of the two. A Fall 2021 study conducted by Google revealed that over 75% of survey respondents expect hybrid work to become a standard practice within their organization within the next three years.  Thus, two years after the world abruptly shifted to widespread adoption of remote work, we are dec...