Progress announced the launch of Progress Data Cloud, a managed Data Platform as a Service designed to simplify enterprise data and artificial intelligence (AI) operations in the cloud.
Tidelift announced a broad new set of capabilities as part of the Tidelift Subscription that expand customers’ ability to utilize Tidelift’s maintainer-validated data to make more informed decisions about open source packages and minimize open source-related risk.
These new capabilities are the culmination of years of work by Tidelift to identify the secure software development practices with the largest impact on improving open source security, and then pay maintainer partners to ensure these practices remain in place for their projects into the future.
“With open source making up the vast majority of the code in modern applications, and against the backdrop of several recent high-profile security vulnerabilities impacting open source, organizations are urgently seeking innovative ways to ensure their software supply chain is properly maintained and secure,” said Lauren Hanford, VP of Product, Tidelift. “Tidelift is the only company working proactively with open source maintainers to validate that their packages meet the security standards newly codified by government and industry, and paying them for this important work. This allows organizations to make more informed decisions about open source and reduce related risk, while having assurances that the software they depend on will be there in the future.”
Tidelift’s open source package intelligence data is researched and validated by Tidelift and its paid maintainer partners and available via the Tidelift Subscription. Tidelift automates the data collection, curates and structures the data, and provides APIs to easily integrate with existing workflows and business intelligence tools.
Organizations can save time by letting Tidelift do the work to collect open source intelligence data at scale, across millions of open source packages. This helps them reduce the time they spend analyzing individual packages and helps them make better decisions more quickly.
The Tidelift Subscription includes:
- First-party maintainer-sourced data. Tidelift partners directly with the maintainers of thousands of the most popular open source packages and pays them to validate that they follow secure development practices like those outlined by government and industry, such as the NIST Secure Software Development Framework and the OpenSSF Scorecards project. This provides organizations with unique first-party, maintainer-sourced insights available only via the Tidelift Subscription.
- Automated, structured, and centralized data. Tidelift aggregates data across multiple upstream package manager ecosystems and source repositories into a centralized and structured format.
- Tidelift human-researched data. The upstream data is analyzed and further researched by the Tidelift data team with the aim of providing more contextualized insights for our customers.
Tidelift Subscription also provides:
- A standardized attestations report, to be used as evidence that the open source dependencies in an organization’s applications follow secure software development best practices.
- A solution to help organizations dynamically track attestations for open source components going into their product and keep the attestations current in an automated manner.
For organizations that rely heavily on open source software but struggle with a lack of visibility regarding package usage across the organization or those concerned that development teams are downloading and using packages that have not been evaluated against organizational risk parameters, Tidelift continues to offer a premier solution for managing open source.
The software bill of materials functionality, included in the Tidelift Subscription, allows organizations to build a centralized inventory of all open source components being used across the organization. This makes it easy to quickly identify every release of a compromised package when remediating vulnerabilities.
Through the Tidelift Subscription, organizations are able to implement open source standards consistently, across all of their development teams, ensuring developers are only using approved open source components that follow secure software development practices. Tidelift then continuously evaluates the packages being used against the set of organizationally-defined open source standards to ensure compliance over time, while also making use of Tidelift’s enhanced data intelligence capabilities to help organizations make good decisions regarding the security and maintenance practices of the components included in their software bills of materials.
Industry News
Sonar announced the release of its latest Long-Term Active (LTA) version, SonarQube Server 2025 Release 1 (2025.1).
Idera announced the launch of Sembi, a multi-brand entity created to unify its premier software quality and security solutions under a single umbrella.
Postman announced the Postman AI Agent Builder, a suite empowering developers to quickly design, test, and deploy intelligent agents by combining LLMs, APIs, and workflows into a unified solution.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of CubeFS.
BrowserStack and Bitrise announced a strategic partnership to revolutionize mobile app quality assurance.
Mendix, a Siemens business, announced the general availability of Mendix 10.18.
Red Hat announced the general availability of Red Hat OpenShift Virtualization Engine, a new edition of Red Hat OpenShift that provides a dedicated way for organizations to access the proven virtualization functionality already available within Red Hat OpenShift.
Contrast Security announced the release of Application Vulnerability Monitoring (AVM), a new capability of Application Detection and Response (ADR).
Red Hat announced the general availability of Red Hat Connectivity Link, a hybrid multicloud application connectivity solution that provides a modern approach to connecting disparate applications and infrastructure.
Appfire announced 7pace Timetracker for Jira is live in the Atlassian Marketplace.
SmartBear announced the availability of SmartBear API Hub featuring HaloAI, an advanced AI-driven capability being introduced across SmartBear's product portfolio, and SmartBear Insight Hub.
Azul announced that the integrated risk management practices for its OpenJDK solutions fully support the stability, resilience and integrity requirements in meeting the European Union’s Digital Operational Resilience Act (DORA) provisions.
OpsVerse announced a significantly enhanced DevOps copilot, Aiden 2.0.