Tidelift Introduces New Open Source Intelligence Capabilities
October 18, 2023

Tidelift announced a broad new set of capabilities as part of the Tidelift Subscription that expand customers’ ability to utilize Tidelift’s maintainer-validated data to make more informed decisions about open source packages and minimize open source-related risk.

These new capabilities are the culmination of years of work by Tidelift to identify the secure software development practices with the largest impact on improving open source security, and then pay maintainer partners to ensure these practices remain in place for their projects into the future.

“With open source making up the vast majority of the code in modern applications, and against the backdrop of several recent high-profile security vulnerabilities impacting open source, organizations are urgently seeking innovative ways to ensure their software supply chain is properly maintained and secure,” said Lauren Hanford, VP of Product, Tidelift. “Tidelift is the only company working proactively with open source maintainers to validate that their packages meet the security standards newly codified by government and industry, and paying them for this important work. This allows organizations to make more informed decisions about open source and reduce related risk, while having assurances that the software they depend on will be there in the future.”

Tidelift’s open source package intelligence data is researched and validated by Tidelift and its paid maintainer partners and available via the Tidelift Subscription. Tidelift automates the data collection, curates and structures the data, and provides APIs to easily integrate with existing workflows and business intelligence tools.

Organizations can save time by letting Tidelift do the work to collect open source intelligence data at scale, across millions of open source packages. This helps them reduce the time they spend analyzing individual packages and helps them make better decisions more quickly.

The Tidelift Subscription includes:

- First-party maintainer-sourced data. Tidelift partners directly with the maintainers of thousands of the most popular open source packages and pays them to validate that they follow secure development practices like those outlined by government and industry, such as the NIST Secure Software Development Framework and the OpenSSF Scorecards project. This provides organizations with unique first-party, maintainer-sourced insights available only via the Tidelift Subscription.

- Automated, structured, and centralized data. Tidelift aggregates data across multiple upstream package manager ecosystems and source repositories into a centralized and structured format.

- Tidelift human-researched data. The upstream data is analyzed and further researched by the Tidelift data team with the aim of providing more contextualized insights for our customers.

Tidelift Subscription also provides:

- A standardized attestations report, to be used as evidence that the open source dependencies in an organization’s applications follow secure software development best practices.

- A solution to help organizations dynamically track attestations for open source components going into their product and keep the attestations current in an automated manner.

For organizations that rely heavily on open source software but struggle with a lack of visibility regarding package usage across the organization or those concerned that development teams are downloading and using packages that have not been evaluated against organizational risk parameters, Tidelift continues to offer a premier solution for managing open source.

The software bill of materials functionality, included in the Tidelift Subscription, allows organizations to build a centralized inventory of all open source components being used across the organization. This makes it easy to quickly identify every release of a compromised package when remediating vulnerabilities.

Through the Tidelift Subscription, organizations are able to implement open source standards consistently, across all of their development teams, ensuring developers are only using approved open source components that follow secure software development practices. Tidelift then continuously evaluates the packages being used against the set of organizationally-defined open source standards to ensure compliance over time, while also making use of Tidelift’s enhanced data intelligence capabilities to help organizations make good decisions regarding the security and maintenance practices of the components included in their software bills of materials.

Share this

Industry News

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.

April 25, 2024

SmartBear has added no-code test automation powered by GenAI to its Zephyr Scale, the solution that delivers scalable, performant test management inside Jira.

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.