Sonatype Expands Support for Rust
March 31, 2025

Sonatype expanded support for software development in Rust via the Cargo registry to the entire Sonatype product suite.

With the addition of Cargo support, Rust developers can leverage Sonatype’s tools to identify and mitigate potential vulnerabilities, block malicious open source from entering software development, and enforce security policies.

Predicted to become a top ten TIOBE coding language in 2025, Rust is designed for building efficient, reliable applications that prioritize security and memory safety, making it a programming language of choice for critical infrastructure and federal systems software.

Sonatype now provides Rust developers with:

- Enhanced Security: Developers can now automatically detect and remediate vulnerabilities within Rust packages and dependencies, reducing the risk of supply chain attacks and blocking malicious Rust packages.

- Compliance Assurance: Ensure Rust components comply with organizational policies and regulatory requirements, giving developers peace of mind in meeting security and legal obligations.

- Ongoing Monitoring: Continuous monitoring of Rust dependencies to quickly address newly discovered vulnerabilities without interrupting the software development lifecycle.

- Component Delivery: Cargo support in Sonatype Nexus Repository speeds up delivery and ensures continuous open source component delivery, even during outages.

- Comprehensive Insights: Gain visibility into open source Rust components being used across teams, and enforce security gates that align with best practices for secure software development.

"As Rust continues to gain momentum in the open source community, we are excited to extend our security and compliance capabilities to support its developers," said Brian Fox, Co-founder and CTO of Sonatype. "Our goal is to empower organizations to innovate confidently, knowing that their software supply chains are safeguarded. With Cargo support, Rust developers can now benefit from the same rigorous security and governance practices that thousands of organizations rely on for other popular programming languages."

With the addition of Cargo support, Sonatype reaffirms its commitment to offering comprehensive, next-generation open source management and security solutions that meet the evolving needs of the development community. Organizations that depend on Sonatype’s platform can now easily integrate Rust into their development pipelines, leveraging advanced security and governance features to ensure a resilient and compliant software infrastructure.

“Rust addresses critical challenges in software development, offering memory safety and concurrency without sacrificing performance,” said Joel Marcey, Director of Technology at The Rust Foundation. “Providing an opportunity for organizations small and large to build with Rust is an important step in furthering mainstream adoption for secure software development via memory-safe languages.”

Share this

Industry News

April 14, 2025

LambdaTest announced the launch of the HyperExecute MCP Server, an enhancement to its AI-native test orchestration platform, HyperExecute.

April 14, 2025

Cloudflare announced Workers VPC and Workers VPC Private Link, new solutions that enable developers to build secure, global cross-cloud applications on Cloudflare Workers.

April 14, 2025

Nutrient announced a significant expansion of its cloud-based services, as well as a series of updates to its SDK products, aimed at enhancing the developer experience by allowing developers to build, scale, and innovate with less friction.

April 10, 2025

Check Point® Software Technologies Ltd.(link is external) announced that its Infinity Platform has been named the top-ranked AI-powered cyber security platform in the 2025 Miercom Assessment.

April 10, 2025

Orca Security announced the Orca Bitbucket App, a cloud-native seamless integration for scanning Bitbucket Repositories.

April 10, 2025

The Live API for Gemini models is now in Preview, enabling developers to start building and testing more robust, scalable applications with significantly higher rate limits.

April 09, 2025

Backslash Security(link is external) announced significant adoption of the Backslash App Graph, the industry’s first dynamic digital twin for application code.

April 09, 2025

SmartBear launched API Hub for Test, a new capability within the company’s API Hub, powered by Swagger.

April 09, 2025

Akamai Technologies introduced App & API Protector Hybrid.

April 09, 2025

Veracode has been granted a United States patent for its generative artificial intelligence security tool, Veracode Fix.

April 09, 2025

Zesty announced that its automated Kubernetes optimization platform, Kompass, now includes full pod scaling capabilities, with the addition of Vertical Pod Autoscaler (VPA) alongside the existing Horizontal Pod Autoscaler (HPA).

April 08, 2025

Check Point® Software Technologies Ltd.(link is external) has emerged as a leading player in Attack Surface Management (ASM) with its acquisition of Cyberint, as highlighted in the recent GigaOm Radar report.

April 08, 2025

GitHub announced the general availability of security campaigns with Copilot Autofix to help security and developer teams rapidly reduce security debt across their entire codebase.

April 08, 2025

DX and Spotify announced a partnership to help engineering organizations achieve higher returns on investment and business impact from their Spotify Portal for Backstage implementation.

April 07, 2025

Appfire announced its launch of the Appfire Cloud Advantage Alliance.