No video

The Tidelift Subscription: Eliminating risk from bad open source packages

  Рет қаралды 187

Tidelift

Tidelift

Күн бұрын

Bad open source packages can slow down your team and create risks for your organization's revenue, data, and customers. Tidelift helps reduce reliance on such packages by partnering with maintainers of thousands of open source projects, ensuring they are healthier and more secure. With the Tidelift Subscription, organizations can evaluate and monitor packages, eliminate bad ones, and improve overall security, productivity, and application quality.
Learn more at: tidelift.com/
Transcription:
Using bad open source packages is slowing your team down and creating risk to your organization's revenue, data, and customers. When you don't know where end-of-life, abandoned, or insecure packages exist in your applications, your only defense is to scan for existing vulnerabilities and fix what you find. Bad packages lead to more vulnerabilities, many of which are difficult to fix. This is making your application development team less productive and creating more risk for your security team to manage. Tidelift helps you proactively reduce your organization's reliance on bad open source packages. We are the only company that partners with the maintainers of 1000s of the most relied upon open source packages and pays them to make their projects healthier and more secure. Our maintainer partners implement enterprise-grade secure software development practices and document the practices they follow.
By using Tidelift recommendations to identify and eliminate bad packages in their applications, organizations can reduce security risk by eliminating attack entry points, improve productivity by reducing vulnerability fire drills, improve application quality by building with healthy and resilient open source packages, and improve operational efficiency by saving costly manual package evaluation time.
In fact, one large organization saved over $1.6 million in manual package evaluation time and eliminated over 3000 points of risk in applications running in production.
With the Tidelift Subscription, organizations are able to evaluate packages before pulling them in for application development to monitor the open source packages they already have in use, to identify and eliminate potentially bad packages they've already adopted, and to reinforce at-risk packages to keep them from becoming bad. Tidelift's package intelligence can easily be integrated into your preferred workflows by using our web UI seen here, through our command line interface, or by using our flexible APIs.
The most unique aspect about the Tidelift Subscription is that it reinforces at risk packages to keep them from becoming bad in the first place. Tidelift customers play a direct role in ensuring the packages they rely on keep getting better, because package maintainers are paid in part based on customer usage. Maintainers use this income to improve the secure development practices they have in place to document these practices and to commit to maintaining them over time. This means that customers can use open source with confidence, knowing that experienced maintainers have made the commitment to ensure their project follows enterprise grade secure software development practices and that they have the income they need to ensure it stays resilient and healthy into the future.
Please contact us to learn more about how your organization can reduce security risk from bad open source packages, while also ensuring the open source you rely on keeps getting better.

Пікірлер: 1
@rekit7351
@rekit7351 Ай бұрын
I like it. It's nice to see a company focus on open-source project maintainers. You might want to include a link to your company website.
How to use Tidelift to select better packages
6:51
Tidelift
Рет қаралды 157
ПОМОГЛА НАЗЫВАЕТСЯ😂
00:20
Chapitosiki
Рет қаралды 27 МЛН
CHOCKY MILK.. 🤣 #shorts
00:20
Savage Vlogs
Рет қаралды 28 МЛН
女孩妒忌小丑女? #小丑#shorts
00:34
好人小丑
Рет қаралды 38 МЛН
UniFi Cloud Gateway MAX! Setup & Comparison | UCG-Max Ubiquiti Networks
25:38
Finding our way out of the CVE dungeon
2:03
Tidelift
Рет қаралды 10
Essential Guide to Cybersecurity in Today's Connected Era
1:14
RAG from the Ground Up with Python and Ollama
15:32
Decoder
Рет қаралды 28 М.
#9 - Dax Raad: Local-First SaaS
1:02:55
Local First Podcast
Рет қаралды 6 М.
MLOps and the Future of AI
46:03
Raghav Dua
Рет қаралды 829
How to Stop Ransomware Attacks Before They Start
2:46
Optrics Engineering
Рет қаралды 59
An example of how security teams respond to CVEs
1:48
Tidelift
Рет қаралды 23