Donald Fischer
@dff
Followers
2K
Following
6K
Media
123
Statuses
2K
Pay the maintainers! ๐ฑ CEO & co-founder @Tidelift. Compiler & package manager enthusiast.
Joined December 2006
Big news! Sonar has entered a definitive agreement to acquire Tidelift to enhance the security and resilience of open source software. Together, weโre raising the bar for code quality and security. Read the blog post from our CEO Donald Fischer:
sonarsource.com
Code quality and security leader to address code-level issues in software supply chain in addition to first-party and AI-generated code
12
3
18
Spoke to @PallardyCarrie for @InformationWeek on @CISAgov's Secure by Design pledge, OSS maintainers, and what comes next: "@tidelift is not only applying the principles in the pledge to its own software, but also helping open source maintainers achieve the pledge goals."
0
0
5
Fun fact: this @finosfoundation panel live right now was the first panel we filmed for #Upstream2024 this year! And now is finally your chance to hear from #finserv experts like @mindthegabz, @tosha_ellison, and @jm_stuff. @dff is your host. Join here: https://t.co/qe14DVM1Ra
0
2
2
Live now! ๐ฃ #Upstream2024 Two of @CISAgov's leading security experts, @jackhcable & @aevavoom, join @dff to provide insights on the industry-wide effort they are leading to make #security a core business requirement in products ๐ Watch here: https://t.co/x1uVo0Ml7E
0
1
3
๐ฅ It's a new Changelog & Friends! ๐ก Is it too late to opt out of AI? ๐คฉ with @luis_in_brief from @tidelift ๐ซก with @jerodsanto & @adamstac ๐ง
0
2
1
The xz Hack Revealed a Looming $8.8 Trillion Infrastructure Disaster https://t.co/bGhITDh3rs
@luis_in_brief #xzhack #security #cybersecurity #hacking
thenewstack.io
Just like our roads, bridges, electrical grid and airports will deteriorate without public investment, so will our software infrastructure without action.
0
4
4
"The XZ utils hack brings into stark relief the risks of under-investing in the health and resilience of the open source software supply chain [that] enterprise organizations rely on," @tidelift's @dff says.
XZ Utils Scare Exposes Hard Truths About Software Security: https://t.co/fjuupcD2jw by @jaivijayan
0
1
0
Software liability changes are coming. Are you ready? ๐ @tidelift CEO @dff shares highlights from new gov't #cybersecurity developments and offers recommended next steps towards demonstrating that your business is following the prescribed best practices https://t.co/EhVfjrzew4
0
1
0
We're so happy to share that @tidelift has officially joined @FINOSFoundation, the Fintech Open Source Foundation! ๐ Tidelift CEO @dff talks about why this is an exciting development over on our blog: https://t.co/jepmfBRWRg Read our press release:
๐ #FINOS Welcomes Six Industry Leaders As New Members, Enhancing Buy-Side Connectivity, #Cloud, & Supply Chain Security Initiatives! https://t.co/nM5RmnSmuh๐
@BlackRock @AladdinbyBLK @Microsoft @PublicisSapient @gitlab @syntasso @tidelift @tradeHeader #OpenSource #FinTech
0
1
0
Gutsy manifesto from @unisonweb: Developing cloud software today is complicated in a very strange way: a lot of the work you end up doing is not programming. What could be possible if you rethought this from the programming language up? They did. https://t.co/fJ2oPAnots
0
3
13
Weโre officially in the new year ๐ Whatโs to come? ๐ค Join us Thurs, Jan. 18 at 2 p.m. ET, when @tidelift co-founders @dff & @luis_in_brief, @RedMonk analyst @drkellyannfitz, & npm maintainer @ljharb come together to look into their crystal balls ๐ฎ https://t.co/mz4FYFSWPp
0
3
5
Tune in tomorrow to see what my brilliant fellow panelists (@BrittanyIstenes, @ljharb, and @tidelift co-founders @dff & @luis_in_brief) predict for #OSS in 2024
This Thursday, Jan. 18 at 2 p.m. ET! ๐ฃ Explore the possibilities and hear from our casual panel on their #OSS security predictions for 2024 ๐ RSVP now โถ๏ธ https://t.co/t0w0kWHMsq
0
4
8
Our @tidelift response to @ONCD RFI: Open source developers are long on passion, but short on time. Pay independent maintainers to ensure, and attest to, the secure software development practices followed by their projects. We brought the data. https://t.co/RNZriTLGem
0
0
0
What could you do with first-party open source software intelligence data, built in partnership with upstream maintainers? Need to comply with new government cybersecurity regulations? Check out @tidelift's new API & compliance reporting capabilities! https://t.co/x3PCFhDjlc
0
0
1
This week @CISAgov published the Open Source Software Security Roadmap and in it, the agency highlighted the need to support a secure and sustainable #OSS ecosystem https://t.co/6vyvDu4dkZ
0
1
1
CISA's new Open Source Software Security Roadmap highlights plans to: ๐ Establish @CISAgov's role in supporting the security of OSS ๐ Drive visibility into OSS usage and risks โก Reduce risks to the federal government ๐ Harden the OSS ecosystem https://t.co/P4zyFP27Ai
0
0
0
Ahead of #OSSummitEU, we explored the matter of how #opensource #maintainers can get paid. Thanks to @ljharb@TweetfromHilary @dff @code_barbarian and Stormy Peters of @github for their help. https://t.co/9JZ6sWLuDf
thenewstack.io
The world runs on code maintained largely by an army of unpaid hobbyists. It's not sustainable. Who's trying to change that?
1
3
6
Get the TL;DR from @tidelift CEO @dff in @securityblvd on the latest U.S. government cybersecurity requirements and what they mean for software vendors selling to the government https://t.co/gT7NckLU34
0
3
1