Behind the Baseline: Reflecting on the launch of the Open Source Project Security Baseline

Behind the Baseline: Reflecting on the launch of the Open Source Project Security Baseline

It's been a while since I've shared an update on the work Sonatype is doing in the open source ecosystem, so I'm excited to share an update on a few things we're doing in the space — and how it led to the creation of a new security standard in ... Read More

Stop the Low-Quality Contribution Plague

I was in a discussion thread with folks from Cloud Native Computing Foundation and Kubernetes today, and this phrase came up again. The context was something along the lines of… “we’re afraid that will encourage low-quality contributions.” ... Read More