Newsletters




Sonar’s Tidelift Acquisition Bolsters Code Quality and Security for Open Source


Sonar, the code quality and security leader, sets its sights on Tidelift, a provider of software supply chain security solutions for mitigating open source software risk, having entered a definitive agreement for acquisition. With both companies propelled by a mission to improve the developer experience, this acquisition strengthens Sonar’s capacity to address code quality issues and security risks latent within code. 

The popularity of open source is dampened by its inherent risk, where malicious code can easily infiltrate enterprise infrastructure through the adoption of open source components. To help secure the open source space, Tidelift pays the maintainers behind thousands of the world’s most influential open source projects to adhere to software development security best practices. When paid, these open source maintainers are 55% more likely to implement crucial security and maintenance practices than their unpaid counterparts, according to Tidelift. 

Sonar’s commitment to the developer experience—as illustrated by its orchestration of the coding lifecycle from code to commit to refactor—aligns with Tidelift’s dedication to open source security. With this acquisition, Sonar will be able to extend its coverage to open source libraries, serving to enhance the level of code quality and security across the board. 

“Tidelift and Sonar are naturally aligned through a common vision—improve code everywhere and supercharge the developer experience. We have been impressed with Tidelift’s approach to improving open source software and look forward to welcoming the team to Sonar,” said Tariq Shaukat, CEO of Sonar. “Tidelift provides insight into many factors that could adversely impact applications relying on open source, so that developers can remediate issues proactively at the point they are introduced.” 

“Against a backdrop of high-profile security issues impacting open source, like the Log4Shell and XZ Utils vulnerabilities, technology leaders have a strategic imperative to ensure that the open source code they incorporate into their applications meets enterprise-grade quality and security standards,” said Donald Fischer, CEO and co-founder of Tidelift. “By combining Tidelift and Sonar’s unique capabilities, organizations will have a complete solution for managing code quality and security across internally developed, AI-generated, and now open source code.” 

To learn more about Sonar and Tidelift, please visit https://www.sonarsource.com/ or https://tidelift.com/.

Sponsors