Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Qualys Cloud Security offers a vulnerability analysis plug-in specifically designed for the CI/CD tool Jenkins, with plans to expand to additional platforms such as Bamboo, TeamCity, and CircleCI in the near future. Users can conveniently download these plug-ins straight from the container security module. This integration allows security teams to engage in the DevOps workflow, ensuring that vulnerable images are blocked from entering the system, while developers receive practical insights to address vulnerabilities effectively. It is possible to establish policies aimed at preventing the inclusion of vulnerable images in repositories, with settings adjustable based on factors like vulnerability severity and particular QIDs. The plug-in also provides an overview of the build, detailing vulnerabilities, information on software that can be patched, available fixed versions, and the specific image layers affected. Given that container infrastructure is inherently immutable, it is essential for containers to be consistent with the original images they are created from, thus necessitating rigorous security measures throughout the development lifecycle. By implementing these strategies, organizations can enhance their ability to maintain secure and compliant container environments.

Description

Sonatype Repository Firewall is designed to safeguard your software development pipeline from malicious open-source packages by utilizing AI-driven detection to intercept potential threats. By monitoring and analyzing over 60 signals from public repositories, the platform ensures that only secure components enter your SDLC. It provides customizable risk profiles and policies that allow automatic blocking of risky packages before they are integrated. With Sonatype Repository Firewall, organizations can maintain high standards of security and compliance, while enhancing DevSecOps collaboration and preventing supply chain attacks.

API Access

Has API Yes 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

BitSight Yes 
C1Risk Yes 
Check Point Exposure Management Yes 
CircleCI Yes 
Complyance Yes 
CyberDNA Command and Control Center Yes 
Cyclops Yes 
Docker Yes 
Graylog Yes 
HivePro Uni5 Yes 
KernelCare Enterprise Yes 
Kroll Cyber Risk Yes 
Maverix No 
Onit Yes 
Refold Yes 
Splunk Cloud Platform Yes 
ThreatAdvisor Yes 
anecdotes Yes 
appNovi Yes 

Integrations

BitSight No 
C1Risk No 
Check Point Exposure Management No 
CircleCI No 
Complyance No 
CyberDNA Command and Control Center No 
Cyclops No 
Docker No 
Graylog No 
HivePro Uni5 No 
KernelCare Enterprise No 
Kroll Cyber Risk No 
Maverix Yes 
Onit No 
Refold No 
Splunk Cloud Platform No 
ThreatAdvisor No 
anecdotes No 
appNovi No 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux Yes 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) Yes 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

Qualys

Founded

1999

Country

United States

Website

www.qualys.com/apps/container-security/

Vendor Details

Company Name

Sonatype

Founded

2008

Country

United States

Website

www.sonatype.com/products/sonatype-repository-firewall

Product Features

Container Security

Access Roles / Permissions No 
Application Performance Tracking No 
Centralized Policy Management No 
Container Stack Scanning No 
Image Vulnerability Detection No 
Reporting No 
Testing No 
View Container Metadata No 

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring No 
Source Code Analysis No 
Third-Party Tools Integration No 
Training Resources No 
Vulnerability Detection No 
Vulnerability Remediation No 

Alternatives

Alternatives

Aqua Reviews

Aqua

Aqua Security