Hi all,
The latest version of Sonatype IQ Server version 177 has been released and is freely available for download for all existing users.
Announcing Sonatype SBOM Manager!
With this release, we are proud to announce our brand new offering, SBOM Manager, powered by Sonatype IQ Server.
SBOM Manager combines our best-in-class component scanning and vulnerability data with market-leading SBOM management support to provide procurement, compliance, and security teams with the tools they need to manage SBOMs for their software and the SBOMs they receive for third-party software.
Contact your Customer Success representative to hear how SBOM Manager may fit your compliance needs. See the SBOM Manager documentation for details on our launch features and capabilities.
New Features in Sonatype Lifecycle
With this release we are also announcing two new dashboards, Dependency Scorecard, and Supply Chain Monitoring, available under Data Insights for Sonatype IQ Server versions 171 and higher.
These dashboards are designed to enable users to grapple with the complexities of the ever-evolving realm of vulnerabilities in open-source supply chains.
Dependency Scorecard
Evaluate your upgrade decisions, based on the placement (App Score) of your applications or libraries in the Dependency Scorecard quadrants. The interactive dashboard allows you to review the key factors that affect the App Score of each application, and plan corrective actions.
Supply Chain Monitoring
Examine the effectiveness of your Sonatype Lifecycle instance as it protects your development pipelines against vulnerabilities. Your Supply Chain Monitoring dashboard scores can be used as guidelines to improve the Lifecycle adoption rate by increasing the number of applications being managed, improving application scanning rates, or better managing critical vulnerabilities.
Notable Bug Fixes
Fix for an issue that did not provide an option to set non-proxy hosts while using Sonatype IQ CLI.
For more detailed information on release 177 and tracking resolved issues, refer to the release notes.