<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=705633339897683&amp;ev=PageView&amp;noscript=1">

Featured

New NSA, CISA, ODNI best practices for securing the open source software supply chain

Last week, in a response to the ever-growing list of software supply chain attacks (SolarWinds and Log4Shell specifically), the U.S. National ...
Donald Fischer
by Donald Fischer
on September 6, 2022

Preparing for the wave of open source funding

By Seth Larson on September 1, 2022
Seth Larson is the lead maintainer of popular Python project urllib3. Seth has been a Tidelift maintainer partner since 2019. He originally wrote ...

Why software composition analysis tools aren't enough

By Kristina Kaldenbach on August 30, 2022
Open source is the modern application development platform because of all of the amazing benefits it provides that speed up development. Yet reliance ...

recap: Unleash the potential in your organization: Socially responsible contribution

By Kristina Kaldenbach on August 25, 2022
On June 7, 2022 Tidelift hosted an event called Upstream, a one-day celebration of open source, the developers who use it, and the maintainers who ...

Tidelift at Digital Engineering Conference 2022

By Kristina Kaldenbach on August 23, 2022
We are excited to head back to Utah for another in-person event! This time we will be exhibiting at the Digital Engineering Conference in Ogden on ...

Recap: Maintainer state of the union panel

By Caitlin Bixby on August 18, 2022
On June 7, 2022 Tidelift hosted an event called Upstream, a one-day celebration of open source, the developers who use it, and the maintainers who ...

Tidelift completes SOC 2 Type 2 examination

By Jeremy Katz on August 16, 2022
Security reigns supreme here at Tidelift. Because we are in the business of helping your organization ensure its supply chain is secure and ...

Digging into the data: Open source software repo supply chain attacks

By Tieg Zaharia on August 2, 2022
I had just wrapped up some internal Tidelift research on open source software supply chain compromises a few weeks ago when I saw PyPI's announcement ...

Open source citizenship panel: What do we owe each other?

By Josh Simmons on July 27, 2022
While working at Google open source in 2018, Cat Allman and I partnered with the world's most respected leaders in enterprise open source and the ...

Tidelift’s take on the U.S. Cyber Safety Review Board Report on Log4Shell vulnerability

By Donald Fischer on July 15, 2022
Yesterday, the U.S. Department of Homeland Security released the first report from the recently created Cyber Safety Review Board (CSRB), reviewing ...

Don't miss the latest from Tidelift

Filter by Topic