Sonatype Platform Browser Extension

Shift Security Left with the Sonatype Platform Browser Extension - Scan Open Source Repositories for known Vulnerabilities.
What is Sonatype Platform Browser Extension?
Sonatype Platform Browser Extension is a Chromium browser extension that works with the Sonatype Platform to empower Developers to make better choices earlier in the Software Development Lifecycle. Connect to your Organization's Sonatype Lifecycle Server and get instant risk insight while browsing public Open Source Registries.

Extension stats

Users: 2,000+
Rating: 5.00 (12)
Version: 2.19.0 (Last updated: 2024-09-04)
Creation date: 2023-07-10
Risk impact: Moderate risk impact
Risk likelihood: Moderate risk likelihood
Manifest version: 3
Permissions:
  • activeTab
  • declarativeContent
  • background
  • scripting
  • storage
  • tabs
Size: 5.33M

Other platforms

Not available on Firefox
Not available on Edge
Want to check extension ranking and stats more quickly for other Chrome extensions? Install Chrome-Stats extension to view Chrome-Stats data as you browse the Chrome Web Store.
Chrome-Stats extension

Extension summary

Analyze keywords

This extension for Chromium browsers works with the Sonatype Platform to empower Developers to make better choices earlier in the Software Development Lifecycle.

Connect this extension to your Organization's Sonatype Lifecycle Server and get instant risk insight as you browse public Open Source Registries such as Maven Central (for Java), NPM (for Javascript), PyPi (for Python) and many many more.

This extension supersedes our previous extension (Nexus IQ Chrome Extension) which is being retired by the end of 2023.

User reviews

These summaries are automatically generated weekly using AI based on recent user reviews. Chrome Web Store does not verify user reviews, so some user reviews may be inaccurate, spammy, or outdated.
Pros
  • Helps identify high-risk security vulnerabilities in OSS components before downloading
  • Facilitates early decision-making in the software development lifecycle (SDLC)
  • Provides insights into security and legal implications of components
  • User-friendly and easy to integrate into the development process
  • Useful for Sonatype customers
Cons
    Most mentioned
    • Shift left in the SDLC
    • Analyzing OSS components for security vulnerabilities
    • Researching open source components
    Recent reviews
    I use this all the time. As developers are initially considering which component to use in their application, they get information while looking at the component in the OSS repository without doing anything. Awesome for shifting left selecting the best component rather than remediating downstream!
    by Chris Wolters, 2024-05-09

    A great tool for analyzing OSS components on the web for high-risk security vulnerabilities prior to downloading for use. Prevent mistakes early on in the SDLC by alerting on insecure packages before they are built in to application code.
    by Neil Schloth, 2023-08-16

    The ultimate in shifting left!
    by Ben Hartley, 2023-07-14
    View all user reviews

    Extension safety

    Risk impact

    Sonatype Platform Browser Extension may not be safe to use and it requires some risky permissions. Exercise caution when installing this extension. Review carefully before installing.

    Risk likelihood

    Sonatype Platform Browser Extension is probably trust-worthy. Prefer other publishers if available. Exercise caution when installing this extension.

    Upgrade to see risk analysis details

    Promo images

    Sonatype Platform Browser Extension small promo image
    Small promo image

    Similar extensions

    Here are some Chrome extensions that are similar to Sonatype Platform Browser Extension: