Fulton, Md., Aug. 18, 2026 (GLOBE NEWSWIRE) -- Sonatype®, the company helping enterprises build with confidence in the AI era, today announced new capabilities for Sonatype Guide, the intelligence layer for AI-speed software development, including Agent P, which automates software maintenance, and Security Events, which gives a real-time view into the most important incidents impacting development. As developers and AI agents assemble software faster than traditional review processes were built to handle, Guide helps them choose safe components at the point of selection, automate dependency decisions, and fix what is broken across human-led and AI-assisted workflows.
Sonatype Research Labs also unveiled The AI-Era Software Assembly Line, a new report analyzing four years of enterprise software development data that found enterprise application creation has accelerated almost 5× in the AI era. At the same time, modern applications carry over 4× more Critical and High-severity vulnerabilities, though the median age of unresolved vulnerabilities is down 59%. Teams are remediating faster, but software creation and risk are accelerating faster still.
“AI is changing the math of software development. We’re building more software, faster, but we’re also introducing risk faster than traditional security processes can absorb it,” said Brian Fox, Co-founder and CTO of Sonatype and Steward of Maven Central. “The answer can’t be to put another review step at the end. We need to make better decisions at the moment software is assembled, whether that decision is being made by a developer or an AI agent.”
Sonatype Guide is designed to bring that control directly into the development process, helping teams make better dependency decisions, automate maintenance, and act on risk without slowing the pace of software creation. With Guide, developers:
- Move control to the point of component selection: Sonatype Guide applies organizational policies across vulnerabilities, malware, licenses, and component quality so developers and AI agents can choose trusted components before they create downstream problems.
- Know what needs fixing without piecing together the story themselves: Security Events provides one place to understand critical open source vulnerabilities and malicious package incidents, with the context and guidance needed to quickly determine impact and response.
- Automate dependency management at AI-speed: Agent P upgrades components, validates changes, and resolves compatibility issues before developer review, turning dependency maintenance into completed, merge-ready changes instead of rework.
“Developers shouldn’t have to choose between moving at AI speed and understanding the software they’re bringing into the organization,” said Mitchell Johnson, Chief Product Development Officer at Sonatype. “Guide brings the intelligence, policy, and automation together so human and agentic teams can make those decisions in the flow of development.”
Get started with Sonatype Guide for free today at https://guide.sonatype.com. To read the full analysis from Sonatype Research Labs, visit https://www.sonatype.com/resources/research/the-ai-era-software-assembly-line.
About Sonatype
Sonatype is the company that accelerates agentic software development with confidence. Trusted by thousands of enterprises and millions of developers, Sonatype helps organizations build with confidence by governing the open source, AI-generated, and third-party components that power modern software. As the steward of Maven Central and the company behind Nexus Repository, Sonatype provides unmatched visibility into how software is built, consumed, and secured — helping teams move faster, reduce risk, and ship software with confidence at AI scale. To learn more about Sonatype, please visit www.sonatype.com.

Sonatype press@sonatype.com