Sonatype
Certifications and attestations: SOC 2 Type IIISO/IEC 27001
As listed on Sonatype's trust center (evidence) ; reports themselves are usually shared on request.
Documents
| Document | Verified | Changed | Evidence |
|---|---|---|---|
| Trust center vanta | snapshot | ||
| Privacy policy | snapshot | ||
| Terms | snapshot | ||
| Security page | snapshot | ||
| Status page statuspage | snapshot | ||
| Security advisories | snapshot |
Subprocessors
None extracted.
Security record
What public security catalogs list for Sonatype, in their words.
Known exploited vulnerabilities
2 vulnerabilities in Sonatype's software that CISA lists as exploited in the wild.
| CVE | Product | Vulnerability | Listed |
|---|---|---|---|
| CVE-2019-7238 | Nexus Repository Manager | Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability | evidence |
| CVE-2020-10199 | Nexus Repository | Sonatype Nexus Repository Remote Code Execution Vulnerability | evidence |
Service status
1 incident in the last 90 days (0 major or critical, 1 minor, 0 with no stated impact) · typically resolved in 11 min
| Began | Incident | Impact | Lasted |
|---|---|---|---|
| Increased Response Times for Application Evaluations | minor | 11 min evidence |
As Sonatype's status page reports its own incidents (scheduled maintenance left out), read every few hours since .
Changes
None since tracking began.