
Tidelift provides the tools, data, and strategies that help organizations assess risk and improve the health, security, and resilience of the open source used in their applications.

Tidelift partners directly with maintainers and pays them to validate the open source software organizations rely on meets enterprise standards now and into the future.
Join us June 7, 2022, for Upstream, a one-day celebration of open source, the developers who use it, and the maintainers who make it.



Get an complete view of open source in use across the organization, including transitive dependencies while dynamvically generating up-to-date SBOMs after every build.
LEARN MOREMake more informed decisions with human-reserached, validated, and normalized metadata from Tidelift and maintainer partners -- and share them across the organization.
LEARN MORE

Centralize open source security, maintenance, and licensing policies and standards while empowering developers to self-serve from catalogs of approved components.
LEARN MOREValidate that the components you use meet emerging enterprise standards—now and into the future—with help from Tidelift and our maintainer partners.
LEARN MORE



Continuously inventory application dependencies while creating up-to-date and risk-reviewed software bills of materials (SBOMs) for all applications. Identify and measure risks and easily review any new dependency information.
Keep constant watch over project health with security vulnerability advice and license annotation provided by Tidelift and maintainer partners, and make informed decisions about which releases to approve.


Combine Tidelift standards with organizational policies to create a repository of curated, tracked, and managed open source components. Custom catalogs enable tracking of internal “inner source” dependencies as well.
Historically, software composition analysis (SCA) tools were one primary way to get better visibility into open source security, maintenance, and licensing risk. But, by themselves, they are not enough.
Inclusive is one of our core values at Tidelift. So we were delighted and inspired when our friends at AWS were interested in collaborating with us on a panel discussion about inclusive practices in open source software development.
Tidelift host Kanish Sharma and guest speaker Jim Mercer, IDC research vice president, dived into these challenges and discussed the best approach to addressing them.