Sonatype Software Supply Chain Security
Workflow capability for software supply chain security using Sonatype Lifecycle. Covers application portfolio management, policy violation monitoring, vulnerability intelligence, component analysis, SBOM generation, and waiver management. Used by DevSecOps engineers, security teams, and compliance officers.
What You Can Do
MCP Tools
list-applications
List all applications in the Sonatype Lifecycle portfolio
create-application
Register a new application in Sonatype Lifecycle
get-application
Get application details from Sonatype Lifecycle
list-policy-violations
List policy violations for an application
list-policy-waivers
List policy waivers for an owner
search-component
Search for a component by hash or PURL to get vulnerability and policy data
get-vulnerability
Get detailed vulnerability information by CVE or Sonatype reference ID
list-application-reports
List scan reports for a specific application
generate-spdx-sbom
Generate an SPDX Software Bill of Materials for an application scan