SlideShare une entreprise Scribd logo
1  sur  29
Télécharger pour lire hors ligne
Sonatype Nexus Demo
Code smarter. Fix faster. Be secure.
Automate software supply chain management to accelerate
developer innovation.
• Sonatype Nexus Overview
• Nexus Feature
• Nexus integration with CI/CD
• 實機展示
• Sonatype Price
• Nexus version compare
• DevOps Support
• Q&A
Nexus Overview
Nexus is a repository manager. It allows you to proxy,
collect, and manage your dependencies so that you
are not constantly juggling a collection of JARs.
It makes it easy to distribute your software. Internally,
you configure your build to publish artifacts to Nexus
and they then become available to other developers.
What is Nexus?
DevSecOps
Sonatype Nexus Repository Pro
Nexus Firewall
Sonatype Nexus Lifecycle
Sonatype Feature
• Advanced Binary Fingerprinting — 使用
獨特的漏洞識別,消除開發人員的摩擦,
減少誤報和漏報。
• Content Profile Insights(內容資料洞
察) — 通過減少花在修復安全、許可、架
構和遷移風險上的時間來優化依賴庫的管
理。
• Deep Code Analysis(深度代碼分析) — 了
解關鍵性能和可靠性問題以及開發人員修
復率,以衡量程式碼品質有效性。
Discover risk the right way — with precise and
accurate data.
• Advanced Policy Controls — 根據應用
程序數據和 SDLC 階段自動執行安全策
略和法律合規義務。
• Continuous Monitoring — 在幾分鐘
內檢測已佈署應用程序中新發現的漏洞。
• Infrastructure as Code Rules — 使開
發人員能夠在開發早期即可發現並修復。
Innovate faster without compromising quality or
security
• Early Warning Detection — 在使用 Sonatype
的 Nexus Intelligence 進入開發管道之前阻止
和防止惡意行為和惡意軟件注入威脅。
• Perimeter Control — 通過自動策略實施自動
防止依賴混淆攻擊進入存儲庫。
• Behavioral Inspection — 通過基於行為的安全
策略的自動檢查,從構建到運行時保護容器。
Protect the integrity of code, delivery pipelines,
and operating environments.
• #7 - Speedier Builds
• #6 - Saving the bandwidth of Central Maven Repositories
• #5 - Predictability and Stability
• #4 - Control and Auditing
• #3 - Ability to Deploy 3rd-party Artifacts
• #2 - Ability to Host Internal Repositories
• #1 - Ability to Host Public Repositories
Why Nexus?
Nexus integration with CI/CD
Create
Branch
Pipeline trigger Code
Quality & Security
Scan Create Pull
Request
Trigger Build &
Test & Deploy
Code Quality & Code
Security Scan
Gitlab Runner
deploy artifact
to GCP
Auto Code Quality &
Code Security Scan
in Client
Define Scan
Rule & Project
Push Code &
Code Review
Nexus IQ CLI
Docker Container
Analysis
Get OSS
Scan
Vulnerability
Build Artifacts
& Scan
Vulnerability
Artifacts Manager & Scan
Vulnerability
1.
2.
4.
5.
3.
6.
7.
8.
9.
11.
12.
10.
Sonatype Full Platform Workflow
實機展示
Sonatype Price
https://www.sonatype.com/products/pricing?hsLang=en-us
Nexus version compare
Repository Oss vs Pros
https://www.sonatype.com/products/repository-oss-vs-pro-
features
1. Stage和Build推廣
2. SAML/SSO、企業LDAP整合
3. 儲存空間擴展與遷移零停機
4. Pro提供進階Repository健康檢查報告
5. 個別Repository搬移
6. 可佈署到npm和Docker
7. 彈性故障切換
8. 原廠支援和專門的客戶成功團隊
Technical support & training
Technical support & training
原廠技術支援
項目 時間
Q&A by email or
Sonatype support system
購買後一年.由Sonatype開
出License時間起計
What’s Consultant Hours
戴博斯企業專業的顧問輔導
FB 粉絲專頁
官方網站

Contenu connexe

Tendances

롯데닷컴의 AWS 클라우드 활용 사례 - AWS Summit Seoul 2017
롯데닷컴의 AWS 클라우드 활용 사례 - AWS Summit Seoul 2017롯데닷컴의 AWS 클라우드 활용 사례 - AWS Summit Seoul 2017
롯데닷컴의 AWS 클라우드 활용 사례 - AWS Summit Seoul 2017
Amazon Web Services Korea
 
AWS DMS를 통한 오라클 DB 마이그레이션 방법 - AWS Summit Seoul 2017
AWS DMS를 통한 오라클 DB 마이그레이션 방법 - AWS Summit Seoul 2017AWS DMS를 통한 오라클 DB 마이그레이션 방법 - AWS Summit Seoul 2017
AWS DMS를 통한 오라클 DB 마이그레이션 방법 - AWS Summit Seoul 2017
Amazon Web Services Korea
 

Tendances (20)

Kubernetes - Security Journey
Kubernetes - Security JourneyKubernetes - Security Journey
Kubernetes - Security Journey
 
Kubernetes Basics
Kubernetes BasicsKubernetes Basics
Kubernetes Basics
 
Kubernetes Architecture | Understanding Kubernetes Components | Kubernetes Tu...
Kubernetes Architecture | Understanding Kubernetes Components | Kubernetes Tu...Kubernetes Architecture | Understanding Kubernetes Components | Kubernetes Tu...
Kubernetes Architecture | Understanding Kubernetes Components | Kubernetes Tu...
 
Introduction to Nexus Repository Manager.pdf
Introduction to Nexus Repository Manager.pdfIntroduction to Nexus Repository Manager.pdf
Introduction to Nexus Repository Manager.pdf
 
롯데닷컴의 AWS 클라우드 활용 사례 - AWS Summit Seoul 2017
롯데닷컴의 AWS 클라우드 활용 사례 - AWS Summit Seoul 2017롯데닷컴의 AWS 클라우드 활용 사례 - AWS Summit Seoul 2017
롯데닷컴의 AWS 클라우드 활용 사례 - AWS Summit Seoul 2017
 
AKS
AKSAKS
AKS
 
Hands-On Introduction to Kubernetes at LISA17
Hands-On Introduction to Kubernetes at LISA17Hands-On Introduction to Kubernetes at LISA17
Hands-On Introduction to Kubernetes at LISA17
 
EKS Workshop
 EKS Workshop EKS Workshop
EKS Workshop
 
Securing Data in Hadoop at Uber
Securing Data in Hadoop at UberSecuring Data in Hadoop at Uber
Securing Data in Hadoop at Uber
 
Final terraform
Final terraformFinal terraform
Final terraform
 
Azure storage
Azure storageAzure storage
Azure storage
 
Exposing services with Azure API Management
Exposing services with Azure API ManagementExposing services with Azure API Management
Exposing services with Azure API Management
 
Kubernetes
KubernetesKubernetes
Kubernetes
 
Kubernetes Security Best Practices - With tips for the CKS exam
Kubernetes Security Best Practices - With tips for the CKS examKubernetes Security Best Practices - With tips for the CKS exam
Kubernetes Security Best Practices - With tips for the CKS exam
 
NGINX Plus on AWS
NGINX Plus on AWSNGINX Plus on AWS
NGINX Plus on AWS
 
Introduction to Microservices
Introduction to MicroservicesIntroduction to Microservices
Introduction to Microservices
 
AWS DMS를 통한 오라클 DB 마이그레이션 방법 - AWS Summit Seoul 2017
AWS DMS를 통한 오라클 DB 마이그레이션 방법 - AWS Summit Seoul 2017AWS DMS를 통한 오라클 DB 마이그레이션 방법 - AWS Summit Seoul 2017
AWS DMS를 통한 오라클 DB 마이그레이션 방법 - AWS Summit Seoul 2017
 
Azure Arc Overview from Microsoft
Azure Arc Overview from MicrosoftAzure Arc Overview from Microsoft
Azure Arc Overview from Microsoft
 
Introduction to Kubernetes Workshop
Introduction to Kubernetes WorkshopIntroduction to Kubernetes Workshop
Introduction to Kubernetes Workshop
 
Rancher 2.0 Technical Deep Dive
Rancher 2.0 Technical Deep DiveRancher 2.0 Technical Deep Dive
Rancher 2.0 Technical Deep Dive
 

Similaire à DevOps Sonatype Nexus Demo_2023.pdf

Continuous delivery with Jenkins Enterprise and Deployit
Continuous delivery with Jenkins Enterprise and DeployitContinuous delivery with Jenkins Enterprise and Deployit
Continuous delivery with Jenkins Enterprise and Deployit
XebiaLabs
 

Similaire à DevOps Sonatype Nexus Demo_2023.pdf (20)

Linktech Sonatype Nexus Demo.pdf
Linktech Sonatype Nexus Demo.pdfLinktech Sonatype Nexus Demo.pdf
Linktech Sonatype Nexus Demo.pdf
 
DevSecOps 實踐與 GitHub 進階安全: 建立安全的開發流程
DevSecOps 實踐與 GitHub 進階安全: 建立安全的開發流程DevSecOps 實踐與 GitHub 進階安全: 建立安全的開發流程
DevSecOps 實踐與 GitHub 進階安全: 建立安全的開發流程
 
Integrate Security into DevOps - SecDevOps
Integrate Security into DevOps - SecDevOpsIntegrate Security into DevOps - SecDevOps
Integrate Security into DevOps - SecDevOps
 
Overcoming Security Challenges in DevOps
Overcoming Security Challenges in DevOpsOvercoming Security Challenges in DevOps
Overcoming Security Challenges in DevOps
 
AddingtheSecToDevOpsBSides (1).pptx for Bsides Nairobi 22 with Joylynn Kirui
AddingtheSecToDevOpsBSides (1).pptx for Bsides Nairobi 22 with Joylynn KiruiAddingtheSecToDevOpsBSides (1).pptx for Bsides Nairobi 22 with Joylynn Kirui
AddingtheSecToDevOpsBSides (1).pptx for Bsides Nairobi 22 with Joylynn Kirui
 
Golismero
GolismeroGolismero
Golismero
 
ContinuousSecurity, Beyond Automation.pdf
ContinuousSecurity, Beyond Automation.pdfContinuousSecurity, Beyond Automation.pdf
ContinuousSecurity, Beyond Automation.pdf
 
Jumping from Continuous Integration to Continuous Delivery with Jenkins Enter...
Jumping from Continuous Integration to Continuous Delivery with Jenkins Enter...Jumping from Continuous Integration to Continuous Delivery with Jenkins Enter...
Jumping from Continuous Integration to Continuous Delivery with Jenkins Enter...
 
Private cloud day session 5 a solution for private cloud security
Private cloud day session 5 a solution for private cloud securityPrivate cloud day session 5 a solution for private cloud security
Private cloud day session 5 a solution for private cloud security
 
Azure 101: Shared responsibility in the Azure Cloud
Azure 101: Shared responsibility in the Azure CloudAzure 101: Shared responsibility in the Azure Cloud
Azure 101: Shared responsibility in the Azure Cloud
 
SevillaJUG - Unleash the power of your applications with Micronaut® ,GraalVM...
SevillaJUG - Unleash the power of your applications with Micronaut®  ,GraalVM...SevillaJUG - Unleash the power of your applications with Micronaut®  ,GraalVM...
SevillaJUG - Unleash the power of your applications with Micronaut® ,GraalVM...
 
Terrascan - Cloud Native Security Tool
Terrascan - Cloud Native Security Tool Terrascan - Cloud Native Security Tool
Terrascan - Cloud Native Security Tool
 
Simplified, Robust and Speedy Novell Identity Manager Implementation with Des...
Simplified, Robust and Speedy Novell Identity Manager Implementation with Des...Simplified, Robust and Speedy Novell Identity Manager Implementation with Des...
Simplified, Robust and Speedy Novell Identity Manager Implementation with Des...
 
DevSecOps: The Open Source Way for CloudExpo 2018
DevSecOps: The Open Source Way for CloudExpo 2018DevSecOps: The Open Source Way for CloudExpo 2018
DevSecOps: The Open Source Way for CloudExpo 2018
 
Modern Web 2019 從零開始加入自動化資安測試
Modern Web 2019 從零開始加入自動化資安測試Modern Web 2019 從零開始加入自動化資安測試
Modern Web 2019 從零開始加入自動化資安測試
 
Cloud Security vs Security in the Cloud
Cloud Security vs Security in the CloudCloud Security vs Security in the Cloud
Cloud Security vs Security in the Cloud
 
GeeCon Prague 2023 - Unleash the power of your applications with Micronaut®, ...
GeeCon Prague 2023 - Unleash the power of your applications with Micronaut®, ...GeeCon Prague 2023 - Unleash the power of your applications with Micronaut®, ...
GeeCon Prague 2023 - Unleash the power of your applications with Micronaut®, ...
 
4 Outcomes of an Advanced Repo Manager Strategy
4 Outcomes of an Advanced Repo Manager Strategy4 Outcomes of an Advanced Repo Manager Strategy
4 Outcomes of an Advanced Repo Manager Strategy
 
PIACERE - DevSecOps Automated
PIACERE - DevSecOps AutomatedPIACERE - DevSecOps Automated
PIACERE - DevSecOps Automated
 
Continuous delivery with Jenkins Enterprise and Deployit
Continuous delivery with Jenkins Enterprise and DeployitContinuous delivery with Jenkins Enterprise and Deployit
Continuous delivery with Jenkins Enterprise and Deployit
 

Plus de DevOps Tec

Plus de DevOps Tec (7)

Freshservice ppt
Freshservice pptFreshservice ppt
Freshservice ppt
 
Freshdesk ppt
Freshdesk pptFreshdesk ppt
Freshdesk ppt
 
Freshchat PTT
Freshchat PTTFreshchat PTT
Freshchat PTT
 
Kissflow demo ppt
Kissflow demo pptKissflow demo ppt
Kissflow demo ppt
 
Freshworks crm ppt
Freshworks crm pptFreshworks crm ppt
Freshworks crm ppt
 
Freshwork ppt
Freshwork pptFreshwork ppt
Freshwork ppt
 
Asana demo pp
Asana demo ppAsana demo pp
Asana demo pp
 

Dernier

Dernier (20)

INGKA DIGITAL: Linked Metadata by Design
INGKA DIGITAL: Linked Metadata by DesignINGKA DIGITAL: Linked Metadata by Design
INGKA DIGITAL: Linked Metadata by Design
 
Reinforcement Learning – a Rewards Based Approach to Machine Learning - Marko...
Reinforcement Learning – a Rewards Based Approach to Machine Learning - Marko...Reinforcement Learning – a Rewards Based Approach to Machine Learning - Marko...
Reinforcement Learning – a Rewards Based Approach to Machine Learning - Marko...
 
The Evolution of Web App Testing_ An Ultimate Guide to Future Trends.pdf
The Evolution of Web App Testing_ An Ultimate Guide to Future Trends.pdfThe Evolution of Web App Testing_ An Ultimate Guide to Future Trends.pdf
The Evolution of Web App Testing_ An Ultimate Guide to Future Trends.pdf
 
Tree in the Forest - Managing Details in BDD Scenarios (live2test 2024)
Tree in the Forest - Managing Details in BDD Scenarios (live2test 2024)Tree in the Forest - Managing Details in BDD Scenarios (live2test 2024)
Tree in the Forest - Managing Details in BDD Scenarios (live2test 2024)
 
A Guideline to Zendesk to Re:amaze Data Migration
A Guideline to Zendesk to Re:amaze Data MigrationA Guideline to Zendesk to Re:amaze Data Migration
A Guideline to Zendesk to Re:amaze Data Migration
 
The Impact of PLM Software on Fashion Production
The Impact of PLM Software on Fashion ProductionThe Impact of PLM Software on Fashion Production
The Impact of PLM Software on Fashion Production
 
Lessons Learned from Building a Serverless Notifications System.pdf
Lessons Learned from Building a Serverless Notifications System.pdfLessons Learned from Building a Serverless Notifications System.pdf
Lessons Learned from Building a Serverless Notifications System.pdf
 
AI Hackathon.pptx
AI                        Hackathon.pptxAI                        Hackathon.pptx
AI Hackathon.pptx
 
architecting-ai-in-the-enterprise-apis-and-applications.pdf
architecting-ai-in-the-enterprise-apis-and-applications.pdfarchitecting-ai-in-the-enterprise-apis-and-applications.pdf
architecting-ai-in-the-enterprise-apis-and-applications.pdf
 
Workforce Efficiency with Employee Time Tracking Software.pdf
Workforce Efficiency with Employee Time Tracking Software.pdfWorkforce Efficiency with Employee Time Tracking Software.pdf
Workforce Efficiency with Employee Time Tracking Software.pdf
 
Automate your OpenSIPS config tests - OpenSIPS Summit 2024
Automate your OpenSIPS config tests - OpenSIPS Summit 2024Automate your OpenSIPS config tests - OpenSIPS Summit 2024
Automate your OpenSIPS config tests - OpenSIPS Summit 2024
 
KLARNA - Language Models and Knowledge Graphs: A Systems Approach
KLARNA -  Language Models and Knowledge Graphs: A Systems ApproachKLARNA -  Language Models and Knowledge Graphs: A Systems Approach
KLARNA - Language Models and Knowledge Graphs: A Systems Approach
 
Implementing KPIs and Right Metrics for Agile Delivery Teams.pdf
Implementing KPIs and Right Metrics for Agile Delivery Teams.pdfImplementing KPIs and Right Metrics for Agile Delivery Teams.pdf
Implementing KPIs and Right Metrics for Agile Delivery Teams.pdf
 
Workshop: Enabling GenAI Breakthroughs with Knowledge Graphs - GraphSummit Milan
Workshop: Enabling GenAI Breakthroughs with Knowledge Graphs - GraphSummit MilanWorkshop: Enabling GenAI Breakthroughs with Knowledge Graphs - GraphSummit Milan
Workshop: Enabling GenAI Breakthroughs with Knowledge Graphs - GraphSummit Milan
 
The mythical technical debt. (Brooke, please, forgive me)
The mythical technical debt. (Brooke, please, forgive me)The mythical technical debt. (Brooke, please, forgive me)
The mythical technical debt. (Brooke, please, forgive me)
 
Microsoft365_Dev_Security_2024_05_16.pdf
Microsoft365_Dev_Security_2024_05_16.pdfMicrosoft365_Dev_Security_2024_05_16.pdf
Microsoft365_Dev_Security_2024_05_16.pdf
 
Weeding your micro service landscape.pdf
Weeding your micro service landscape.pdfWeeding your micro service landscape.pdf
Weeding your micro service landscape.pdf
 
How to install and activate eGrabber JobGrabber
How to install and activate eGrabber JobGrabberHow to install and activate eGrabber JobGrabber
How to install and activate eGrabber JobGrabber
 
A Deep Dive into Secure Product Development Frameworks.pdf
A Deep Dive into Secure Product Development Frameworks.pdfA Deep Dive into Secure Product Development Frameworks.pdf
A Deep Dive into Secure Product Development Frameworks.pdf
 
5 Reasons Driving Warehouse Management Systems Demand
5 Reasons Driving Warehouse Management Systems Demand5 Reasons Driving Warehouse Management Systems Demand
5 Reasons Driving Warehouse Management Systems Demand
 

DevOps Sonatype Nexus Demo_2023.pdf

  • 1. Sonatype Nexus Demo Code smarter. Fix faster. Be secure. Automate software supply chain management to accelerate developer innovation.
  • 2. • Sonatype Nexus Overview • Nexus Feature • Nexus integration with CI/CD • 實機展示 • Sonatype Price • Nexus version compare • DevOps Support • Q&A
  • 4. Nexus is a repository manager. It allows you to proxy, collect, and manage your dependencies so that you are not constantly juggling a collection of JARs. It makes it easy to distribute your software. Internally, you configure your build to publish artifacts to Nexus and they then become available to other developers. What is Nexus?
  • 8.
  • 11.
  • 12. • Advanced Binary Fingerprinting — 使用 獨特的漏洞識別,消除開發人員的摩擦, 減少誤報和漏報。 • Content Profile Insights(內容資料洞 察) — 通過減少花在修復安全、許可、架 構和遷移風險上的時間來優化依賴庫的管 理。 • Deep Code Analysis(深度代碼分析) — 了 解關鍵性能和可靠性問題以及開發人員修 復率,以衡量程式碼品質有效性。 Discover risk the right way — with precise and accurate data.
  • 13. • Advanced Policy Controls — 根據應用 程序數據和 SDLC 階段自動執行安全策 略和法律合規義務。 • Continuous Monitoring — 在幾分鐘 內檢測已佈署應用程序中新發現的漏洞。 • Infrastructure as Code Rules — 使開 發人員能夠在開發早期即可發現並修復。 Innovate faster without compromising quality or security
  • 14. • Early Warning Detection — 在使用 Sonatype 的 Nexus Intelligence 進入開發管道之前阻止 和防止惡意行為和惡意軟件注入威脅。 • Perimeter Control — 通過自動策略實施自動 防止依賴混淆攻擊進入存儲庫。 • Behavioral Inspection — 通過基於行為的安全 策略的自動檢查,從構建到運行時保護容器。 Protect the integrity of code, delivery pipelines, and operating environments.
  • 15. • #7 - Speedier Builds • #6 - Saving the bandwidth of Central Maven Repositories • #5 - Predictability and Stability • #4 - Control and Auditing • #3 - Ability to Deploy 3rd-party Artifacts • #2 - Ability to Host Internal Repositories • #1 - Ability to Host Public Repositories Why Nexus?
  • 17. Create Branch Pipeline trigger Code Quality & Security Scan Create Pull Request Trigger Build & Test & Deploy Code Quality & Code Security Scan Gitlab Runner deploy artifact to GCP Auto Code Quality & Code Security Scan in Client Define Scan Rule & Project Push Code & Code Review Nexus IQ CLI Docker Container Analysis Get OSS Scan Vulnerability Build Artifacts & Scan Vulnerability Artifacts Manager & Scan Vulnerability 1. 2. 4. 5. 3. 6. 7. 8. 9. 11. 12. 10.
  • 23. Repository Oss vs Pros https://www.sonatype.com/products/repository-oss-vs-pro- features 1. Stage和Build推廣 2. SAML/SSO、企業LDAP整合 3. 儲存空間擴展與遷移零停機 4. Pro提供進階Repository健康檢查報告 5. 個別Repository搬移 6. 可佈署到npm和Docker 7. 彈性故障切換 8. 原廠支援和專門的客戶成功團隊
  • 25. Technical support & training 原廠技術支援 項目 時間 Q&A by email or Sonatype support system 購買後一年.由Sonatype開 出License時間起計
  • 28.