FINOS Platinum and Gold Member Benefit
Blind spots exist for most organizations when it comes to the enforcement of policies around third-party dependency consumption - whether you know it or not!
The FINOS Dependency Consumption Analysis (DCA) initiative powered by Sonatype provides a comprehensive analysis of your organization's dependency management practices, as observed through your download activity from Maven Central.
The integrity and security of the financial services industry software supply chain is critically important— and it begins with each organization understanding their situation with a clear and complete perspective. Through this increased visibility and understanding, FINOS will create opportunities for better knowledge sharing while also shedding light on the most vulnerable parts of the broader financial ecosystem.
We have found that your practices in managing Java dependencies is indicative of behaviors across other ecosystems, such as npm, Python, Ruby, and NuGet. Each of these ecosystems presents substantial risks, particularly the threat of intentional malicious open source components if not properly defended against.
Maven Central is the largest and most important repository in the Java ecosystem, serving as a primary source for open-source libraries and components developers use worldwide. It is the default central repository used by Apache Maven, the widely adopted build automation tool, as well as other build systems like Gradle and SBT. Software built in Java, Android, Scala and other JVM languages use Maven Central as their default destination to fetch open source components. In 2024, it is estimated to serve over 1.4 trillion requests worldwide.
Maintained by Sonatype, Maven Central hosts millions of Java artifacts, facilitating seamless integration into Java projects by providing a standardized way to share and consume these libraries. Maven Central's reliability, security, and accessibility are crucial for the global development community, ensuring that developers can easily access the components they need while maintaining a high standard of trust and safety.