Sonatype secures the software supply chain and protects organizations' vital software development lifecycle(SDLC). The platform unites security teams and developers to accelerate digital innovation without sacrificing security or quality across the SDLC. With users among more than 2,000 organizations and 15 million software developers, Sonatype tools and guidance help users to deliver and maintain exceptional and secure software.
$0
for use of the Sonatype Nexus Repository Community Edition
SourceForge
Score 9.9 out of 10
N/A
SourceForge is a B2B software discovery platform, featuring 4000+ categories in its comparison engine that potential buyers can use to compare software by user reviews, features, pricing, integrations, operating system, and deployment.
- Guidance on remediation is very good - Vulnerability detection is very good - Support is very good - Ability to ask PMs/POs open questions at Office Hours every month is very good - Support for languages is lacking (TIOBE Index Top20) - Some features are un-neededly hidden and make the usage more complex then it needs to be
I recommend SourceForge to anyone or business that needs both commercial and open source software. This platform has a wide variety of software with many categories that allow easy search for any project, in addition to the fact that searches can be done separately (commercial and open source software) so as not to have mixed results which go with different purpose. In addition to the fact that the community of this platform is quite active and that there are always times to discover new projects that can be useful for a company or individual person.
Nexus firewall is a great feature enabled for all our proxy repositories which are used to download the third-party opensource packages.
Nexus IQ is integrated with build stage to analyze the component against evaluation policy. This helps to figure out the application security standards.
Nexus IQ is also having a feature to scan container images before it uploads to our private repository. This is great feature for container platforms.
The overall design that SourceForge has really leaves a lot to be desired, although the entire platform works perfectly, I think that the design should be much more attractive.
There is currently no feature to save your progress on a review you are writing, so if you are writing a review and the browser is closed for some reason, all progress of the written review will be lost.
Sonatype supports more than 200 dev(s). It proves with the repository to store the artifacts. Allows for governance of open source software used by the different teams. It is used by security teams to scan for vulnerabilities in software(s) and in the deployed containers. It helps ensure code quality.
Souceforge was very straightforward and easy to manage. The leads worked for us so there is not a lot else to say about why I'd use it again. This isn't some complicated software product, it is a simple inbound marketing channel that is meant to generate leads and help us with brand awareness and it did exactly that.
Overall experience is great with the Platform; however, I see some opportunity with upgrading the platform as it is missing with data of historical scans to allow reviewer to get view of trend how the application/product development team is considering fixing the issues.
SourceForge is super easy to use and very intuitive. And their support team and campaign managers help whenever we need it. Using SourceForge as a user is easy, and administrating a business software listing is easy as well. They also have great documentation.
We've never had any issues or downtime with SourceForge. Since we've been a user, the platform has never been down. Or at least never that I've noticed.
Sonatype products are great value as I said but a few areas like how products use underlying resources in order to make it further lightweight, is something I would like them to consider.
SourceForge loads extremely quickly whether you're using the front end or administrating your product listing on the back end. All pages are snappy to load--no issues with page speed whatsoever.
I hardly ever use the support on SourceForge, as I have not needed it. Their product works well for me. One time I had to email them and they got back to me the same day, but that's my only experience.
When we first signed up, they pair you with a campaign manager who trained us on how to use the product properly. The product is simple so the training was only about 30 minutes and after that we understood all the features and how to make the most of it. Most of the work came with making a custom landing page and building a follow up process for our sales team.
Out of other products we evaluated before choosing Sonatype, the later looked far more user friendly, easy to understand and work with. This was key for us, as the tool needs to be used by many engineers that don't have security as their main focus. Having a tool that is easy to understand and work with, makes the process of evaluating open source dependencies much easier and appealing for developers.
G2 has a larger commitment time upfront and for a more expensive rate, which wasn't the best option for our team as we were just exploring the resources that existed out there at the time. We preferred Sourceforge as well due to its subscription service, making it easier to commit from the start.
SourceForge has been plenty scalable for us. Our marketing department is able to edit listings and our executives can also log in to the platform if need be for leads and reporting information. SourceForge offers multiple user access and role permissions, so it's pretty scalable and easy to use for our entire team.