Our Community Projects

Here are all our Open Source projects.

Ahab

ARCHIVED
Scan base OS (debian, fedora, alpine) packages for vulnerabilities.
Worked with:
Sonatype OSS Index Sonatype Lifecycle

API Clients (IQ)

golang python typescript api client
Generated API Clients in Go, Python and Typescript for Sonatype IQ Server Manager
Works with:
Sonatype Developer Sonatype Repository Firewall Sonatype Lifecycle Sonatype Lifecycle

API Clients (Repo)

golang java typescript api client
Generated API Clients in Go, Java and Typescript for Sonatype Nexus Repository Manager
Works with:
Sonatype Nexus Repository Manager

AuditJS

javascript nodejs
Scan JavaScript (node.js inclusive) projects for vulnerable third-party dependencies.
Works with:
Sonatype OSS Index Sonatype Lifecycle

Bach

php composer
Scan PHP and Composer projects for vulnerable third-party dependencies.
Works with:
Sonatype OSS Index

Cargo Pants

rust cargo
Cargo subcommand provides a project bill of materials and identifies vulnerabilities.
Works with:
Sonatype OSS Index Sonatype Lifecycle

Chelsea

rubygems
Scan RubyGems powered projects for vulnerable third-party dependencies.
Works with:
Sonatype OSS Index Sonatype Lifecycle

Cheque

c
Scan C projects for vulnerable third-party dependencies.
Works with:
Sonatype OSS Index

Container (IQ)

GRADUATED arm
Container Image built for ARM for Sonatype IQ Server
Worked with:
Sonatype Developer Sonatype Repository Firewall Sonatype Lifecycle Sonatype Lifecycle

Container (Repo)

arm
Container Image built for ARM for Sonatype Nexus Repository Manager
Works with:
Sonatype Nexus Repository Manager

GCP Blobstore

GRADUATED blobstore
Sonatype Nexus Repository Manager Blobstore backed by Google Cloud Storage.
Worked with:
Sonatype Nexus Repository Manager

GitHub Action

GRADUATED ci sbom
GitHub Action for invoking Sonatype Lifecycle scans and obtaining SBOMs
Worked with:
Sonatype Lifecycle

Jake

python conda pip
Scan Python and Conda environments for vulnerable third-party dependencies.
Works with:
Sonatype OSS Index Sonatype Lifecycle

Nancy

golang
Scan Golang projects for vulnerable third-party dependencies.
Works with:
Sonatype OSS Index Sonatype Lifecycle

Nexus CasC Plugin

java
Nexus CasC is a configuration as code plugin for Sonatype Nexus Repository Manager 3
Works with:
Sonatype Nexus Repository Manager

OysterR

r cran
Scan R code for vulnerable third-party dependencies.
Works with:
Sonatype OSS Index

Sherlock Trunks

java gradle
A Gradle plugin that scans the dependencies of a Gradle project for vulnerabilities.
Works with:
Sonatype OSS Index Sonatype Lifecycle

The CLA Bot

cla
Also known as Paul Botsco - this is our CLA Bot.
Works with: