<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=705633339897683&amp;ev=PageView&amp;noscript=1">

Featured

Recap: Life as an open source maintainer after xz

It’s been six weeks since a developer uncovered a hack of epic scope in the popular Linux compression library called xz utils (previously known as ...
Amy Hays
by Amy Hays
on May 15, 2024

Tidelift co-founder and CEO Donald Fischer on the FINOS podcast

By Caitlin Bixby on May 14, 2024
Recently, Tidelift co-founder and CEO Donald Fischer sat down with host of the Fintech Open Source Foundation (FINOS) Open Source in Finance podcast, ...

Tidelift signs the CISA Secure by Design pledge

By Donald Fischer on May 8, 2024
Today, Tidelift was proud to join other leading technology companies during a live ceremony at RSA in San Francisco where we signed the US ...

Product update: Using end-of-life package data to identify and eliminate bad open source packages

By Lauren Hanford on May 7, 2024
Tidelift helps organizations remove risk to their revenue, data, and customers from bad open source packages. Bad packages (by which we mean ...

Tidelift at RSA 2024

By Kristina Kaldenbach on May 1, 2024
We are excited to be heading back to San Francisco for RSA this year! RSA brings together cybersecurity leaders and peers to explore our critical ...

Upstream rewind: the 2023 keynote, the accidental supply chain, and what it means today

By Caitlin Bixby on April 30, 2024
As we count down to this year’s Upstream, we’ll be looking back at Upstream moments from years past. Discover how topics may have changed and how ...

New report from Atlantic Council finds paying maintainers can positively impact open source security

By Lauren Hanford on April 23, 2024
A new report just out last week from the Digital Forensic Research Lab (DFRLab) at the Atlantic Council found that open source projects with funding ...

Is xz actually an open source success story?

By Jeremy Katz on April 17, 2024
It’s been just over two weeks since we all learned about a backdoor that had been slowly and carefully placed in the xz-utils library over a period ...

Paying maintainers: the HOWTO

By Luis Villa on April 15, 2024
As part of the xz discussion, some asserted that “paying maintainers doesn’t work—we tried to give people money and they wouldn’t take it.” Suffice ...

Maintainer panel: Hear from maintainers in a post-xz utils backdoor world

By Amy Hays on April 15, 2024
A few weeks ago, a very sinister, sophisticated hack was uncovered in an obscure but ubiquitous Linux library called xz utils.

Don't miss the latest from Tidelift

Filter by Topic