Open source maintainers: Key to software health and security

Open source has become the foundation of modern application development, with up to 98% of applications incorporating open-source components and open-source code accounting for 70% or more of the typical application. In this Help Net Security video, Do… Continue reading Open source maintainers: Key to software health and security

Paid open-source maintainers spend more time on security

Paid maintainers are 55% more likely to implement critical security and maintenance practices than unpaid maintainers and are dedicating more time to implementing security practices like those included in industry standards like the OpenSSF Scorecard a… Continue reading Paid open-source maintainers spend more time on security

Tidelift improves software supply chain security with open source intelligence capabilities

Tidelift announced a broad new set of capabilities as part of the Tidelift Subscription that expand customers’ ability to utilize Tidelift’s maintainer-validated data to make more informed decisions about open source packages and minimize open source-r… Continue reading Tidelift improves software supply chain security with open source intelligence capabilities

A closer look at the RFI on open-source software security

The U.S. Office of the National Cyber Director (ONCD) released a request for information (RFI) entitled Open-Source Software Security: Areas of Long-Term Focus and Prioritization, which indicates that the U.S. Government’s effort to invest in ope… Continue reading A closer look at the RFI on open-source software security

Unpaid open source maintainers struggle with increased security demands

Ensuring the security of the open-source software that modern organizations depend on is a crucial responsibility of the open source maintainers, especially as attacks on the software supply chain are increasingly common, according to Tidelift. Open so… Continue reading Unpaid open source maintainers struggle with increased security demands

Tidelift raises $27 million to improve open source software supply chain security

Tidelift announced $27 million in Series C funding, led by Dorilton Ventures, with Kaiser Permanente and Atlassian Ventures joining existing investors General Catalyst and Foundry Group. As part of the transaction, Daniel Freeman of Dorilton Ventures h… Continue reading Tidelift raises $27 million to improve open source software supply chain security

The state of open-source software supply chain security in 2022

In this video for Help Net Security, Donald Fischer, CEO at Tidelift, talks about the state of open-source software supply chain security in 2022. Open source is the modern application development platform and is becoming an indispensable part of the s… Continue reading The state of open-source software supply chain security in 2022

Challenges development teams face when building applications with open source

Tidelift released a report providing critical insights into the state and practice of open source software supply chain management. This comprehensive study of nearly 700 technologists, now in its fourth year, explored the most urgent challenges develo… Continue reading Challenges development teams face when building applications with open source

The Internet Was Built on the Free Labor of Open Source Developers. Is That Sustainable?

A look at the complicated business of funding open source software development. Continue reading The Internet Was Built on the Free Labor of Open Source Developers. Is That Sustainable?