Sign in

@buildwithsonatype

@buildwithsonatype.bsky.social
6 followers 0 following 7 posts

Helping developers build with confidence in open source. Stewards of Maven Central. Follow for software supply chain intelligence, Maven Central updates, news and data, and developer conversations.

PostsRepliesMedia
@buildwithsonatype @buildwithsonatype.bsky.social · 01/10/2026
Maven Central publishing limits are now in effect. Most community open source publishers can continue publishing for free. Check your organization’s usage, and share feedback as you have it. Usage: central.sonatype.com/publishing/u... Limits and guidance: central.sonatype.org/publish/mave...
central.sonatype.com
Maven Central: Publishing
Maven Central: Publishing
000
@buildwithsonatype @buildwithsonatype.bsky.social · 03/09/2026
New vulnerability? Malicious package making the rounds? We’re keeping the latest major security events, affected components, and what developers need to know here: guide.sonatype.com/security-eve...
guide.sonatype.com
Security Events | Sonatype Guide
Browse security advisories and threat intelligence from Sonatype Security Research. Get authoritative analysis of major CVEs, supply chain attacks, and malware…
000
@buildwithsonatype @buildwithsonatype.bsky.social · 21/08/2026
91 Spring CVEs → 209,569 affected components. That’s a lot more than 91 things to check. Guide turned a massive coordinated disclosure into something developers can act on, with the affected components, versions, and vulnerability context in one place ↓ guide.sonatype.com/security-eve...
guide.sonatype.com
91 Spring CVEs Affect More Than 209,000 Co… | Sonatype Guide
Broadcom published a large collection of Spring security advisories affecting Spring Framework and related projects, with Sonatype tracking 91 CVEs and more th…
011
@buildwithsonatype @buildwithsonatype.bsky.social · 13/08/2026
For all the new AI security problems, one of Black Hat's loudest messages was remarkably old-school: assume something will get fooled and design so it can't do much damage when it does. Field notes from Vegas: www.sonatype.com/blog/major-t...
sonatype.com
Major Themes at Black Hat 2026
Black Hat explored AI's growing security impact, from vulnerability discovery and prompt injection to why least privilege and security basics still matter.
000
@buildwithsonatype @buildwithsonatype.bsky.social · 20/07/2026
The @sdtimes.bsky.social Editorial Board captured that shift in this year's SD Times 100, recognizing Sonatype alongside other organizations helping development and security teams build with greater confidence. Read the full list: 🔗 sdtimes.com/security/sec...
000
@buildwithsonatype @buildwithsonatype.bsky.social · 16/07/2026
Every AI system has a supply chain and models are only part of the picture. Datasets, open source components, APIs, and agents all shape how AI behaves and where risk can emerge. Great insights from Kate O'Flaherty and Ilkka Turunen: 🔗 insight.scmagazineuk.com/what-is-an-a...
011
@buildwithsonatype @buildwithsonatype.bsky.social · 13/07/2026
We promise not to post "We're excited to announce..." We'd rather show you how attackers are changing software development, what AI means for open source, and the research behind it, drawing on insights from Maven Central, Nexus Repository, and our security research. Welcome to Sonatype.
050