Postman announced Agent Mode, an AI-native assistant that delivers real productivity gains across the entire API lifecycle.
Sonar signed a definitive agreement to acquire Tidelift, a provider of software supply chain security solutions that help organizations manage the risk of open source software.
The acquisition will extend Sonar’s scope of coverage to include open source libraries, in addition to code written by developers and AI – improving the state of open source software and raising the bar for code quality and security everywhere.
Tidelift helps improve the health and security of open source by paying the maintainers behind thousands of the world’s most-relied-upon open source projects to follow secure software development practices. Paid open source maintainers are 55% more likely to implement critical security and maintenance practices than unpaid maintainers.
“Tidelift and Sonar are naturally aligned through a common vision – improve code everywhere and supercharge the developer experience. We have been impressed with Tidelift’s approach to improving open source software and look forward to welcoming the team to Sonar,” said Tariq Shaukat, CEO of Sonar. “Tidelift provides insight into many factors that could adversely impact applications relying on open source, so that developers can remediate issues proactively at the point they are introduced.”
For organizations that write code and build software, Sonar improves developer productivity and accelerates software development by improving the developer experience with actionable insights, high-fidelity issue alerts, and assistance with remediation along the development workflow. By orchestrating the coding lifecycle from code to commit to refactor, with the developer experience at the center, Sonar maximizes developers' potential to deliver excellent, secure code fast.
“Against a backdrop of high-profile security issues impacting open source, like the Log4Shell and XZ Utils vulnerabilities, technology leaders have a strategic imperative to ensure that the open source code they incorporate into their applications meets enterprise-grade quality and security standards,” said Donald Fischer, CEO and co-founder of Tidelift. “By combining Tidelift and Sonar’s unique capabilities, organizations will have a complete solution for managing code quality and security across internally developed, AI-generated, and now open source code.”
The Tidelift offering will continue to be available – there are no immediate planned changes to the current Tidelift product. Tidelift customers and maintainer partners will not experience any disruption to their current experiences.
Additional details will be provided in Q1 2025.
Industry News
Progress Software announced the Q2 2025 release of Progress® Telerik® and Progress® Kendo UI®, the .NET and JavaScript UI libraries for modern application development.
Voltage Park announced the launch of its managed Kubernetes service.
Cobalt announced a set of powerful product enhancements within the Cobalt Offensive Security Platform aimed at helping customers scale security testing with greater clarity, automation, and control.
LambdaTest announced its partnership with Assembla, a cloud-based platform for version control and project management.
Salt Security unveiled Salt Illuminate, a platform that redefines how organizations adopt API security.
Workday announced a new unified, AI developer toolset to bring the power of Workday Illuminate directly into the hands of customer and partner developers, enabling them to easily customize and connect AI apps and agents on the Workday platform.
Pegasystems introduced Pega Agentic Process Fabric™, a service that orchestrates all AI agents and systems across an open agentic network for more reliable and accurate automation.
Fivetran announced that its Connector SDK now supports custom connectors for any data source.
Copado announced that Copado Robotic Testing is available in AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on Amazon Web Services (AWS).
Check Point® Software Technologies Ltd.(link is external) announced major advancements to its family of Quantum Force Security Gateways(link is external).
Sauce Labs announced the general availability of iOS 18 testing on its Virtual Device Cloud (VDC).
Infragistics announced the launch of Infragistics Ultimate 25.1, the company's flagship UX and UI product.
CIQ announced the creation of its Open Source Program Office (OSPO).
Check Point® Software Technologies Ltd.(link is external) announced the launch of its next generation Quantum(link is external) Smart-1 Management Appliances, delivering 2X increase in managed gateways and up to 70% higher log rate, with AI-powered security tools designed to meet the demands of hybrid enterprises.