RSVP: 10 critical things to know before depending on an open source project ⚖️
For maintainers
Login
For maintainers
Log in
Product
PRODUCT
Overview
Scope of support
Pricing
USE CASES
Validated open source
package intelligence
Open source management
and policy compliance
Compliance with government
cybersecurity requirements
Open source cybersecurity
risk mitigation
M-22-18 attestation compliance
(software suppliers)
Open source security
attestation data
Open source compliance / SBOMs
Schedule demo
Resources
All resources
Case Stories
Log4Shell
Guides & Reports
Webinars
Analyst
Documentation
Videos
Blog
Surveys
Government resources
Company
About Tidelift
Press
Contact us
Partnerships
Events
Join the Tidelift team
Blog
Book a custom demo
Featured
Tidelift advisory | “Text4Shell” Apache Commons Text vulnerability: what you need to know and do
In this advisory, we will address the core facts regarding the recently disclosed security vulnerability in the Apache Commons Text project, which ...
by
Donald Fischer
on October 19, 2022
Tidelift advisory | Log4Shell critical vulnerability: what you need to know and do
By
Jeremy Katz
on December 11, 2021
In this advisory, we will address the core facts regarding the recently disclosed security vulnerability in the Apache log4j project, which has been ...
This is a search field with an auto-suggest feature attached.
There are no suggestions because the search field is empty.
Filter by Topic
Maintainers
(89)
Lifters
(81)
Managed open source
(53)
Events
(48)
Upstream
(37)
Government
(34)
Data
(28)
Survey
(28)
open source software supply chain
(28)
Open Source Software
(26)