SHARE
Facebook X Pinterest WhatsApp

Sonatype Launches Guide for Faster, More Secure AI Coding

Sonatype launches Guide, an AI-driven DevSecOps tool that improves coding assistant accuracy, cuts security risks, and delivers real-time secure package guidance.

Written By
thumbnail
Luis Millares
Luis Millares
Dec 9, 2025
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Sonatype, a provider of AI-driven DevSecOps, has unveiled Sonatype Guide — a new developer tool that makes AI-assisted software development faster, safer, and more efficient. 

The new solution aims to address the security and efficiency issues that arise when developers rely on AI coding assistants trained on outdated public data.

Fostering clean and secure AI coding

According to Sonatype, Sonatype Guide helps developers reap the productivity and speed benefits of AI coding assistants while closing the gaps introduced by models trained on aging public datasets.

“AI coding assistants are helping developers move faster, but because AI models are trained on public data that may be months or years out of date, they frequently recommend vulnerable, low-quality, or even imagined packages,” the company said in an official press release.

Sonatype Guide integrations include GitHub Copilot, Claude Code and many more

Guide integrates with popular AI coding assistants, including GitHub Copilot, Google Antigravity, Claude Code, Windsurf, and Cursor, and is powered by Sonatype’s open source intelligence. 

Key capabilities include:

  • MCP Server for AI Coding Assistants: As a high-speed middleware layer between AI coding assistants and Sonatype intelligence, the MCP server intercepts package recommendations in real time — instantly guiding developers to secure, reliable versions before code reaches the repo.
  • Enhanced Open Source Software (OSS) Search for Instant Decisions: A modern search experience that instantly surfaces the lowest-effort, highest-impact fixes and upgrade choices.
  • Enterprise Grade API:  Access to the Nexus One Platform API, including the Sonatype OSSI Index API format, which delivers complete, unrestricted, and backward-compatible access to reliable data.

“Developers love the speed AI coding assistants unlock, but they’re also the ones stuck untangling bad package recommendations or chasing down dependency issues later,” said Mitchell Johnson, chief product development officer at Sonatype. 

“Guide gives developers the help they actually want — real-time intelligence that steers AI toward secure, well-maintained components and cuts out hours of research and rework. It means fewer interruptions, cleaner code from the start, and more time spent building the things that matter.” Johnson added.

Sonatype research backs AI coding concerns over hallucinations

Alongside the product launch, Sonatype shared early findings from an upcoming study on generative AI coding assistants.

According to Sonatype research, leading LLMs used in today’s coding assistants hallucinate software packages up to 27 percent of the time. In practice, this means many models attempt to build or update applications using nonexistent or potentially malicious open-source components.

Sonatype warns that these hallucinations can create rework for development teams, burn LLM tokens, and introduce unnecessary security risks. 

Why Sonatype believes it has the answer to hallucinations

On the flipside, enterprises using Sonatype Guide achieved more than a 300 percent improvement in security outcomes while reducing total security remediation and dependency-upgrade costs by over 5x compared to the leading competitive strategy.

These results came from the same component sample, in which Sonatype produced zero hallucinated versions, delivering fully accurate upgrade guidance.

“Every organization wants to harness the productivity of AI, but they can’t afford to compromise security or long-term maintainability,” said Bhagwat Swaroop, chief executive officer at Sonatype. 

“Guide brings discipline and intelligence to AI-assisted development. It empowers teams to move faster and safer by steering AI toward secure, reliable components and automating the tedious dependency work that slows teams down. This is a significant step forward for the industry and for our customers,” he continued.

thumbnail
Luis Millares

Luis Millares has extensive experience reviewing virtual private networks (VPNs), password managers, and other security software. He has tested and reviewed numerous forms of tech, covering consumer technology like smartphones and laptops, all the way to enterprise software and cybersecurity products. He has authored over 450 online articles on technology and has worked for the leading tech journalism site in the Philippines, YugaTech.com. He currently contributes to the Daily Tech Insider newsletter, providing well-researched insights and coverage of the latest in technology.

Recommended for you...

CrewAI CEO: Human Trust is Core to Autonomous AI Agents
Jordan Smith
Dec 9, 2025
Zendesk, Salesforce Extend Partnerships With AWS at re:Invent
Jordan Smith
Dec 4, 2025
Pax8’s CPO Libby McIlhany on AI Agents, Marketplaces & More
Video: Tackling AI, Tech Debt & Faster AWS Migration with Caylent
Katie Bavoso
Dec 4, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.