Sonatype connector for Okou
Connect Sonatype Lifecycle to inspect applications, policy findings, vulnerabilities, SBOMs, and Sonatype Firewall data through the REST API.
Engineering · User Token
Use Sonatype in Okou
Sonatype Lifecycle and IQ Server REST API for applications, policy findings, vulnerabilities, SBOMs, and Sonatype Firewall read-only workflows.
Once connected, supported Sonatype actions can become steps in a reusable workflow alongside the other services your team uses. Run the workflow once, on a schedule, or when an event starts it.
What you can do with Sonatype
- Read Sonatype organizations visible to the authenticated account.
- Read Sonatype applications and their organization associations.
- Read application reports, scan metadata, dependency trees, and evaluation status.
- Read Sonatype policies and policy-violation details.
- Read policy waivers, waiver requests, reasons, and stale-waiver reports.
- Search evaluated components and read structured component analysis results.
- Read vulnerability details and reachability evidence for authorized reports.
- Read CycloneDX and SPDX SBOM documents for authorized application scans.
How the Sonatype connector works
A connected service becomes one permissioned step in the work you hand off.
- 1
Connect Sonatype
Choose User Token.
- 2
Choose the work
Use only the supported actions your workflow needs.
- 3
Run it your way
Start it once, schedule it, or attach an event trigger.
Connect Sonatype securely
Use the connection method that fits your account and grant only the access the workflow needs.
- User Token
Connector access is controlled per service and per action, so a workflow does not need broader access than the work you ask it to do.
Sonatype connector questions
- What can Okou do with Sonatype?
- Connect Sonatype Lifecycle to inspect applications, policy findings, vulnerabilities, SBOMs, and Sonatype Firewall data through the REST API. Documented actions include: Read Sonatype organizations visible to the authenticated account. Read Sonatype applications and their organization associations.
- How do I connect Sonatype to Okou?
- Connect Sonatype using User Token. The connection controls which supported actions a workflow can use.
- Can Sonatype run in an automated workflow?
- Yes. After it is connected, supported Sonatype actions can run in reusable Okou workflows on demand, on a schedule, or from an event trigger.
More engineering connectors
Explore other connectors in the same product category.
SourceForge
Connect SourceForge to inspect and manage hosted open-source projects, repositories, wikis, tickets, discussions, blogs, exports, tools, and webhooks.
SonarQube Server
Connect SonarQube Server to inspect projects, issues, measures, quality gates, quality profiles, rules, analyses, and instance status through a read-only Web API.
Sourcegraph
Connect Sourcegraph to run the documented read-only GraphQL diagnostics query for the authenticated user.

