Sonatype Nexus IQ Evaluation

Sonatype Nexus IQ Evaluation

Sonatype Nexus IQ Evaluation - Scan Open Source Repositories for known Vulnerabilities.

What is Sonatype Nexus IQ Evaluation?
Sonatype Nexus IQ Evaluation is a Chrome extension allowing users to inspect open source packages for security vulnerabilities before downloading them. It is designed to integrate with a valid Sonatype Nexus Lifecycle instance, allowing for detailed package analysis. The plugin supports multiple package managers across diverse platforms, enabling broad-spectrum inspection of risky open source repositories.
Merlin
Stats
Users: 1,000+
Rating: 5.00 (5)
Version: 1.10.0 (Last updated: 2023-07-14)
Creation date: 2020-05-27
Risk impact: High risk impact
Risk likelihood: Moderate risk likelihood
Manifest version: 2
Permissions:
  • activeTab
  • declarativeContent
  • cookies
  • background
  • storage
  • https://pkgs.alpinelinux.org/
  • https://anaconda.org/anaconda/
  • https://community.chocolatey.org/
  • https://clojars.org/
  • https://cocoapods.org/
  • See more
Size: 2.40M
Stats date:

Other platforms

Not available on Firefox
Not available on Edge
Want to check extension ranking and stats more quickly for other Chrome extensions? Install Chrome-Stats extension to view Chrome-Stats data as you browse the Chrome Web Store.
Chrome-Stats extension
Merlin
Summary

This Chrome Extension works with Sonatype Nexus Lifecycle to inspect an OSS package before you download it. The plugin requires a valid Sonatype Nexus Lifecycle instance. You will be prompted to connect to your Sonatype Nexus IQ Server during setup. Note: Supported by Sonatype.

The extension works with the following package managers and their websites.

  1. .Net – NuGet – https://www.nuget.org/
  2. Alpine – Linux – https://pkgs.alpinelinux.org/
  3. Chocolatey – Windows – https://community.chocolatey.org/
  4. Clojars – Clojure – https://clojars.org/
  5. CocoaPods – iOS – https://cocoapods.org/
  6. Conan – C/C++ – https://conan.io/center/
  7. Conda – Python – https://anaconda.org/anaconda/
  8. Debian – Linux – https://packages.debian.org/
  9. Debian – Linux – https://tracker.debian.org/pkg/
  10. GitHub – releases – https://github.com/*/releases/tag/*
  11. Golang – Go – https://pkg.go.dev/
See more
User reviews
A great tool for analyzing OSS components on the web for high-risk security vulnerabilities prior to downloading for use. Prevent mistakes early on in the SDLC by alerting on insecure packages before they are built in to application code.
by Neil Schloth Neil Schloth, 2020-07-22
View all user reviews
Safety
Risk impact

Sonatype Nexus IQ Evaluation is risky to use as it requires a number of sensitive permissions that can potentially harm your browser and steal your data. Exercise caution when installing this extension. Review carefully before installing. We recommend that you only install Sonatype Nexus IQ Evaluation if you trust the publisher.

Risk likelihood

Sonatype Nexus IQ Evaluation is probably trust-worthy. Prefer other publishers if available. Exercise caution when installing this extension.

Upgrade to see risk analysis details
Promo video
Screenshots
Promo images
Sonatype Nexus IQ Evaluation small promo image
Small promo image
Similar extensions

Here are some Chrome extensions that are similar to Sonatype Nexus IQ Evaluation: