Introducing G2.ai, the future of software buying.Try now
Aikido Security
Sponsored
Aikido Security
Visit Website
Product Avatar Image
Sonatype Lifecycle

By Sonatype

4.2 out of 5 stars
3 star
0%
2 star
0%
1 star
0%

How would you rate your experience with Sonatype Lifecycle?

Aikido Security
Sponsored
Aikido Security
Visit Website
It's been two months since this profile received a new review
Leave a Review

Sonatype Lifecycle Reviews & Product Details

Profile Status

This profile is currently managed by Sonatype Lifecycle but has limited features.

Are you part of the Sonatype Lifecycle team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Sonatype Lifecycle Media

Sonatype Lifecycle Demo - Nexus Lifecycle provides developers feedback inside of the pull request
Manage dependencies in source control with automated pull requests. Nexus Lifecycle integrates with GitHub, GitLab, and Atlassian Bitbucket to automatically generate pull requests for components that violate open source policies. Developers can easily see what versions they should use in orde...
Sonatype Lifecycle Demo - Nexus Lifecycle: customizing OSS policies for your org
Nexus Lifecycle offers policies that can be customized across organizations, applications, compliance standards, and more.
Sonatype Lifecycle Demo - Nexus Lifecycle: edit SCA policies with ease
Edit Nexus Lifecycle policies with ease in our award-winning UX.
Sonatype Lifecycle Demo - Nexus Lifecycle: prevent next-gen OSS attacks with AI/ML
Nexus Lifecycle uses AI and ML to spot adversaries attack vectors that rely on malicious code injection and advanced typo squatting techniques.
Sonatype Lifecycle Demo - Nexus Lifecycle: apply policies based on SDLC stage, application, or organization
Nexus Lifecycle policies can be applied and customized with the click of a button at any stage of your SDLC. Different actions can be taken at various SDLC stages.
Sonatype Lifecycle Demo - Nexus Lifecycle: quickly determine which vulnerable OSS components present the most risk
Nexus Lifecycle dashboards offer a portfolio wide view of risk and remediation priorities.
Product Avatar Image

Have you used Sonatype Lifecycle before?

Answer a few questions to help the Sonatype Lifecycle community

Sonatype Lifecycle Reviews (4)

Reviews

Sonatype Lifecycle Reviews (4)

4.2
4 reviews

Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Vis C.
VC
Software Security Technical Director
Enterprise (> 1000 emp.)
"Best SCA tool in the market for Java, and .NET"
What do you like best about Sonatype Lifecycle?

Zero false positives in component identification and vulnerability reported for those built in Java and .NET. Review collected by and hosted on G2.com.

What do you dislike about Sonatype Lifecycle?

Doesnt work well for components developed in C, C++ and mobile languages Review collected by and hosted on G2.com.

Verified User in Consumer Services
AC
Enterprise (> 1000 emp.)
"Good for Small to Medium Companies"
What do you like best about Sonatype Lifecycle?

I like the ease of use of the application. Review collected by and hosted on G2.com.

What do you dislike about Sonatype Lifecycle?

I'm unable to have more than one admin user. Review collected by and hosted on G2.com.

Verified User in Financial Services
UF
Enterprise (> 1000 emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"So many features, easily configurable and wide support for a lot of languages"
What do you like best about Sonatype Lifecycle?

Good documentation and plugins available to support almost every language Review collected by and hosted on G2.com.

What do you dislike about Sonatype Lifecycle?

Older version don't have as much support as newer ones and it takes a while to upgrade Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Mid-Market (51-1000 emp.)
"Nexus vulnerability scanner."
What do you like best about Sonatype Lifecycle?

Nexus is best vulnerability scanning tool to identify the vulnerabilities and misconfugration in server. Review collected by and hosted on G2.com.

What do you dislike about Sonatype Lifecycle?

Some time nexus generates the false positive result. Review collected by and hosted on G2.com.

There are not enough reviews of Sonatype Lifecycle for G2 to provide buying insight. Below are some alternatives with more reviews:

1
GitLab Logo
GitLab
4.5
(858)
An open source web interface and source control platform based on Git.
2
GitHub Logo
GitHub
4.7
(2,263)
GitHub is the best place to share code with friends, co-workers, classmates, and complete strangers. Over two million people use GitHub to build amazing things together.
3
Wiz Logo
Wiz
4.7
(738)
Wiz is a CNAPP that consolidates CSPM, KSPM, CWPP, vulnerability management, IaC scanning, CIEM, DSPM, and container and Kubernetes security into a single platform.
4
FortiCNAPP Logo
FortiCNAPP
4.4
(384)
FortiCNAPP is a comprehensive Cloud-Native Application Protection Platform (CNAPP) that consolidates Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), Cloud Infrastructure Entitlement Management (CIEM), Kubernetes security, and compliance into a single solution. Using AI-based anomaly detection and behavioral analytics, FortiCNAPP continuously monitors cloud environments to identify misconfigurations, vulnerabilities, and active threats in real time. The platform supports agentless and agent-based deployment models, ensuring flexible coverage across diverse architectures. FortiCNAPP also integrates with the Fortinet Security Fabric, correlating cloud data with network and endpoint insights from FortiGuard, FortiSOAR, and more, delivering full-stack threat context, faster remediation, and unified risk management.
5
Snyk Logo
Snyk
4.5
(123)
Snyk is a security solution designed to find and fix vulnerabilities in Node.js and Ruby apps.
6
Microsoft Defender for Cloud Logo
Microsoft Defender for Cloud
4.4
(303)
Azure Security Center provides security management and threat protection across your hybrid cloud workloads. It allows you to prevent, detect, and respond to security threats with increased visibility.
7
Orca Security Logo
Orca Security
4.6
(222)
Get workload-level visibility into AWS, Azure, and GCP without the operational costs of agents. You could buy three tools instead… but why? Orca replaces legacy vulnerability assessment tools, CSPM, and CWPP. Deploys in minutes, not months.
8
AlgoSec Logo
AlgoSec
4.5
(195)
AlgoSec is a business-driven security management solution.
9
Mend.io Logo
Mend.io
4.3
(112)
Mend.io delivers the first AI native application security platform built for software created by both humans and machines. It empowers organizations to secure AI generated code and embedded AI components like models, agents, MCPs, and RAG pipelines. The unified platform brings together comprehensive capabilities including AI security, SAST, SCA, container scanning, and Mend Renovate providing development and security teams complete visibility into risks across their codebase. With AI powered remediation and prioritization workflows, teams are enabled to quickly resolve issues and reduce risk. With a simple, predictable price model, eliminating per-module costs and minimal reliance on expensive professional services Mend.io is a scalable, proactive, developer-friendly platform for modern AppSec—all in a single platform.
10
Hybrid Cloud Security Logo
Hybrid Cloud Security
4.5
(187)
Hybrid Cloud Security solution, powered by XGen security, delivers a blend of cross-generational threat defense techniques that have been optimized to protect physical, virtual, and cloud workloads.
Show More
Pricing

Pricing details for this product isn’t currently available. Visit the vendor’s website to learn more.

Sonatype Lifecycle Comparisons
Product Avatar Image
Snyk
Compare Now