Tidelift, Inc. — Department of Defense SBIR Phase II: AF211-CSO1
Tidelift, Inc. — SBIR Phase II award from Department of Defense.
- Amount
- $1,499,844
- Agency
- Department of Defense · Defense Advanced Research Projects Agency
- Program / Phase
- SBIR · Phase II
- Topic
- AF211-CSO1
- Solicitation
- X21.1
- NAICS
- —
- Place of performance
- MA
- Period
- 2022-11-30 → 2024-12-31
Description
Open source software has become the modern application development platform across enterprises and governments. More than 90% of professional applications are created using open source components. Furthermore, open source software often comprises 70%+ of the code in any modern application. As software supply chain security makes front page news with the SolarWinds breach impacting multiple US federal agencies and departments, it is more important than ever that application development teams employ a comprehensive approach for managing the open source components that make up their applications. With the advent of programs like Platform One’s DoD Enterprise DevSecOps Services, that new reality is facing DoD application developers as well. DoD application development teams are already exposed to potential compromise by adversary teams through the open source packages they’re using today. Unmanaged third-party open source packages present a clear and immediate supply chain risk at all levels—potentially leading to a catastrophic loss of command and control systems in warfighting situations and a total mission compromise. Tidelift is the largest provider of commercial support and maintenance for community-led open source libraries and packages. By partnering with independent project maintainers through Tidelift, the DoD will get a safe, easy, and cost-effective approach to managing open source components. The Tidelift managed open source solution delivers customizable catalogs of software supply chain components that are actively maintained, secure, and accurately licensed, enabling developers to build and deploy faster and with confidence. Research demonstrates that the big three support challenges for open source software are: Maintenance - Guarantees that the packages they use are maintained Security - Protection from security issues Licensing - Open source license management Without a managed solution, DoD development teams face productivity drains, exposure to adversary attacks through unpatched security vulnerabilities, and intellectual property risks. For the military, assuming responsibility for the maintenance of mission-critical, open source-based systems and applications can be challenging because of the long lifespans of the systems involved and the sheer effort required. Unfortunately, support may not always be readily available. For example, personnel often believe that “somebody out there” can help them address security issues as they arise – when this may not be the case. Open source community members aren’t on call 24/7 and do not deliver service level agreements to users. Fortunately, external vendors can help. Crucially, external vendors can also provide support, taking on responsibility for the open source maintenance piece – thereby enabling military IT to focus on higher-level activities that directly support the mission. -Military Embedded Systems: Harnessing open source innovation in the military with rock-solid security, Nov 2019