Sonar to Acquire Tidelift to Reduce Risk From Open Source Software

Code quality and security leader to address code-level issues in software supply chain in addition to first-party and AI-generated code

AUSTIN and GENEVA – December 17 – Sonar, the code quality and security leader, today announced that it has signed a definitive agreement to acquire Tidelift, a provider of software supply chain security solutions that help organizations manage the risk of open source software. The acquisition will extend Sonar’s scope of coverage to include open source libraries, in addition to code written by developers and AI – improving the state of open source software and raising the bar for code quality and security everywhere. 


With more than 90% of software built using open source components, evaluating open source risks is critical to the sustainability and security of organizations’ applications. Tidelift helps improve the health and security of open source by paying the maintainers behind thousands of the world’s most-relied-upon open source projects to follow industry-leading secure software development practices. Paid open source maintainers are 55% more likely to implement critical security and maintenance practices than unpaid maintainers. 


“Tidelift and Sonar are naturally aligned through a common vision – improve code everywhere and supercharge the developer experience. We have been impressed with Tidelift’s approach to improving open source software and look forward to welcoming the team to Sonar,” said Tariq Shaukat, CEO of Sonar. “Tidelift provides insight into many factors that could adversely impact applications relying on open source, so that developers can remediate issues proactively at the point they are introduced.” 


For organizations that write code and build software, Sonar improves developer productivity and accelerates software development by improving the developer experience with actionable insights, high-fidelity issue alerts, and assistance with remediation along the development workflow. By orchestrating the coding lifecycle from code to commit to refactor, with the developer experience at the center, Sonar maximizes developers' potential to deliver excellent, secure code fast. 


“Against a backdrop of high-profile security issues impacting open source, like the Log4Shell and XZ Utils vulnerabilities, technology leaders have a strategic imperative to ensure that the open source code they incorporate into their applications meets enterprise-grade quality and security standards,” said Donald Fischer, CEO and co-founder of Tidelift. “By combining Tidelift and Sonar’s unique capabilities, organizations will have a complete solution for managing code quality and security across internally developed, AI-generated, and now open source code.” 


Established in 2017, Tidelift customers include a broad range of enterprise technology, federal, and financial institutions, like Cisco, Fannie Mae, and the U.S. Air Force. The Tidelift offering will continue to be available – there are no immediate planned changes to the current Tidelift product. Tidelift customers and maintainer partners will not experience any disruption to their current experiences. 


Additional details will be provided in Q1 2025. To hear more from the Tidelift team, visit their announcement blog


About Tidelift

Tidelift helps organizations improve the health and security of the open source powering their applications. Tidelift partners with leading open source maintainers to provide the only source for human-validated data about the secure development practices followed by the world’s most critical open source projects. This enables organizations to use open source with confidence, so they can create more incredible software, even faster. https://tidelift.com/


About Sonar   

Sonar helps prevent code quality and security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it—your internal team or genAI—resulting in more secure, reliable, and maintainable software. Rooted in the open source community, Sonar’s solutions support over 30 programming languages, frameworks, and infrastructure technologies. 


Today, Sonar is used by 7M+ developers and 400K organizations worldwide, including the DoD, Microsoft, NASA, MasterCard, Siemens, and T-Mobile. To learn more about Sonar, please visit: https://www.sonar.com



Media Contact  

Rachel Adam for Sonar  

(401) 261-1707

press@sonarsource.com 


###


  • 法律文件
  • 信任中心
  • Follow SonarSource on Twitter
  • Follow SonarSource on Linkedin

© 2008-2024 SonarSource SA. All rights reserved. SONAR, SONARSOURCE, SonarQube for IDE, SonarQube Server, SonarQube Cloud, and CLEAN AS YOU CODE are trademarks of SonarSource SA.