Mendix, a Siemens business, announced the general availability of Mendix 10.18.
Sonar signed a definitive agreement to acquire Tidelift, a provider of software supply chain security solutions that help organizations manage the risk of open source software.
The acquisition will extend Sonar’s scope of coverage to include open source libraries, in addition to code written by developers and AI – improving the state of open source software and raising the bar for code quality and security everywhere.
Tidelift helps improve the health and security of open source by paying the maintainers behind thousands of the world’s most-relied-upon open source projects to follow secure software development practices. Paid open source maintainers are 55% more likely to implement critical security and maintenance practices than unpaid maintainers.
“Tidelift and Sonar are naturally aligned through a common vision – improve code everywhere and supercharge the developer experience. We have been impressed with Tidelift’s approach to improving open source software and look forward to welcoming the team to Sonar,” said Tariq Shaukat, CEO of Sonar. “Tidelift provides insight into many factors that could adversely impact applications relying on open source, so that developers can remediate issues proactively at the point they are introduced.”
For organizations that write code and build software, Sonar improves developer productivity and accelerates software development by improving the developer experience with actionable insights, high-fidelity issue alerts, and assistance with remediation along the development workflow. By orchestrating the coding lifecycle from code to commit to refactor, with the developer experience at the center, Sonar maximizes developers' potential to deliver excellent, secure code fast.
“Against a backdrop of high-profile security issues impacting open source, like the Log4Shell and XZ Utils vulnerabilities, technology leaders have a strategic imperative to ensure that the open source code they incorporate into their applications meets enterprise-grade quality and security standards,” said Donald Fischer, CEO and co-founder of Tidelift. “By combining Tidelift and Sonar’s unique capabilities, organizations will have a complete solution for managing code quality and security across internally developed, AI-generated, and now open source code.”
The Tidelift offering will continue to be available – there are no immediate planned changes to the current Tidelift product. Tidelift customers and maintainer partners will not experience any disruption to their current experiences.
Additional details will be provided in Q1 2025.
Industry News
Red Hat announced the general availability of Red Hat OpenShift Virtualization Engine, a new edition of Red Hat OpenShift that provides a dedicated way for organizations to access the proven virtualization functionality already available within Red Hat OpenShift.
Contrast Security announced the release of Application Vulnerability Monitoring (AVM), a new capability of Application Detection and Response (ADR).
Red Hat announced the general availability of Red Hat Connectivity Link, a hybrid multicloud application connectivity solution that provides a modern approach to connecting disparate applications and infrastructure.
Appfire announced 7pace Timetracker for Jira is live in the Atlassian Marketplace.
SmartBear announced the availability of SmartBear API Hub featuring HaloAI, an advanced AI-driven capability being introduced across SmartBear's product portfolio, and SmartBear Insight Hub.
Azul announced that the integrated risk management practices for its OpenJDK solutions fully support the stability, resilience and integrity requirements in meeting the European Union’s Digital Operational Resilience Act (DORA) provisions.
OpsVerse announced a significantly enhanced DevOps copilot, Aiden 2.0.
Progress received multiple awards from prestigious organizations for its inclusive workplace, culture and focus on corporate social responsibility (CSR).
Red Hat has completed its acquisition of Neural Magic, a provider of software and algorithms that accelerate generative AI (gen AI) inference workloads.
Code Intelligence announced the launch of Spark, an AI test agent that autonomously identifies bugs in unknown code without human interaction.
Checkmarx announced a new generation in software supply chain security with its Secrets Detection and Repository Health solutions to minimize application risk.
SmartBear has appointed Dan Faulkner, the company’s Chief Product Officer, as Chief Executive Officer.
Horizon3.ai announced the release of NodeZero™ Kubernetes Pentesting, a new capability available to all NodeZero users.