Tidelift, Inc. — Department of Defense SBIR Phase II: AFX234-DCSO2
Tidelift, Inc. — SBIR Phase II award from Department of Defense.
- Amount
- $1,249,997
- Agency
- Department of Defense · Air Force
- Program / Phase
- SBIR · Phase II
- Topic
- AFX234-DCSO2
- Solicitation
- X23.4
- NAICS
- —
- Place of performance
- MA
- Period
- 2023-02-03 → 2024-11-12
Description
Open source software has become the modern application development platform across the Department of Defense, as well as broader industrial enterprises. More than 90% of professional applications today are created using open source components. Furthermore, open source software often comprises 70% or more of the code in any modern application. However, supply chain attacks on open source software grew 650% in 2021. A recent example of a high profile attack in the open source supply chain is the Log4Shell vulnerability. Log4Shell is a widely used logging library, found in most large enterprise Java applications. In the wake of the Log4Shell vulnerability, there have been widespread reports of the vulnerability being used to install crypto-mining software, serve as the entry point for botnets, and extract configurations, environmental variables and other sensitive data from vulnerable servers. Software tools alone can’t comprehensively address open source software supply chain challenges like Log4Shell—we also need to address the human element. Without a tools + people solution integrated into DevSecOps platforms like Platform One’s Big Bang and Party Bus, DOD development teams face productivity drains, exposure to adversary attacks through unpatched security vulnerabilities, and intellectual property risks. Tidelift provides the only solution capable of ensuring that community-led open source libraries and packages upstream meet production-ready standards. By partnering upstream with independent (community led) project maintainers through Tidelift (the actual people who have created or maintain critical projects), the Air Force and DOD will gain access to a safe, easy, consistent and cost-effective approach to managing open source components proactively. Tidelift is the only organization that is actively working directly with the open source community to improve data quality and ensure that Software Bill of Materials (“SBOMs”) have accurate, up to date and rich data. In addition, The Tidelift managed open source solution delivers customizable catalogs of software supply chain components that are actively maintained, secure, and accurately licensed, enabling developers to build and deploy faster and with confidence.