Sonatype Platform Browser Extension

Shift Security Left with the Sonatype Platform Browser Extension - Scan Open Source Repositories for known Vulnerabilities.
What is Sonatype Platform Browser Extension?
Sonatype Platform Browser Extension is a Chromium browser extension that works with the Sonatype Platform to empower Developers to make better choices earlier in the Software Development Lifecycle. Connect to your Organization's Sonatype Lifecycle Server and get instant risk insight while browsing public Open Source Registries.

Extension stats

Users: 2,000+
Rating: 5.00 (12)
Version: 2.20.0 (Last updated: 2024-11-14)
Creation date: 2023-07-10
Risk impact: Moderate risk impact
Risk likelihood: Moderate risk likelihood
Manifest version: 3
Permissions:
  • activeTab
  • declarativeContent
  • background
  • scripting
  • storage
  • tabs
Size: 5.32M

Other platforms

Not available on Firefox
Not available on Edge
Want to check extension ranking and stats more quickly for other Chrome extensions? Install Chrome-Stats extension to view Chrome-Stats data as you browse the Chrome Web Store.

Extension summary

Analyze keywords

This extension for Chromium browsers works with the Sonatype Platform to empower Developers to make better choices earlier in the Software Development Lifecycle.

Connect this extension to your Organization's Sonatype Lifecycle Server and get instant risk insight as you browse public Open Source Registries such as Maven Central (for Java), NPM (for Javascript), PyPi (for Python) and many many more.

This extension supersedes our previous extension (Nexus IQ Chrome Extension) which is being retired by the end of 2023.

User reviews

These summaries are automatically generated weekly using AI based on recent user reviews. Chrome Web Store does not verify user reviews, so some user reviews may be inaccurate, spammy, or outdated.
Pros
  • Helps identify high-risk security vulnerabilities in OSS components before downloading
  • Provides insights into security and legal implications of components
  • Facilitates early decision-making in the software development lifecycle (SDLC)
  • Useful for researching open source components being considered for applications
Cons
    Most mentioned
    • Useful plugin for analyzing OSS components
    • Prevents mistakes early in the SDLC
    • Supports shifting left approach in development
    Recent reviews
    I use this all the time. As developers are initially considering which component to use in their application, they get information while looking at the component in the OSS repository without doing anything. Awesome for shifting left selecting the best component rather than remediating downstream!
    by Chris Wolters, 2024-05-09

    A great tool for analyzing OSS components on the web for high-risk security vulnerabilities prior to downloading for use. Prevent mistakes early on in the SDLC by alerting on insecure packages before they are built in to application code.
    by Neil Schloth, 2023-08-16

    The ultimate in shifting left!
    by Ben Hartley, 2023-07-14
    View all user reviews

    Extension safety

    Risk impact

    Sonatype Platform Browser Extension requires a few sensitive permissions. Exercise caution before installing.

    Risk likelihood

    Sonatype Platform Browser Extension is probably trust-worthy. Prefer other publishers if available. Exercise caution when installing this extension.

    Upgrade to see risk analysis details

    Promo images

    Sonatype Platform Browser Extension small promo image
    Small promo image

    Similar extensions

    Here are some Chrome extensions that are similar to Sonatype Platform Browser Extension: