Use Tidelift’s package, release, and vulnerability APIs to give your teams access to a continuously curated stream of validated data about vetted components they need to make intelligent decisions, faster.
Curate catalogs of vetted, approved open source components with validated licenses that follow secure software development practices, then continuously curate them against the set of organizationally-defined open source policies.
The best way for organizations selling software to the U.S. government to comply with mandatory secure software development requirements, by providing the data they need to attest to the secure development practices of the open source components used in their applications.
Tidelift pays open source maintainers to ensure their projects follow industry-standard secure software development practices (like those found in the NIST Secure Software Development Framework and the OpenSSF Scorecards). We work together with our maintainer partners to provide this unique and valuable data, so you know if, when, and how your open source will be secured and maintained.
Within days of using the Tidelift application, the Distributive team found a potential vulnerability that npm-audit hadn’t, and quickly and safely fixed those issues with Tidelift’s CLI tool.
Check out the new state of the open source maintainer report which included 11 key headlines coming out of our new survey of over 300 open source maintainers.
Tidelift named a Cool Vendor in the May 2022 Gartner Cool Vendors in Software Engineering