Tender Automation

Direktvergabe

Deutschland – Forschungsdienste – Eclipse Foundation-Project

1 Los

Beschreibung

As a research and development service, the contract is excluded from the scope of public procurement law (cf. § 116(1)(2) GWB). The Eclipse Foundation AISBL is the host to some of the most widely utilized Java-based open source technologies, including Eclipse Jetty, Jakarta EE, Eclipse IDE, and Eclipse Glassfish. Part of the project is the implementation of improvements to the Eclipse Foundation projects’ infrastructure and security. The procurements objective is to help some of the key projects of the Eclipse Foundation to harden their software supply chain, by continuously monitoring for new vulnerabilities and generating Software Bills of Materials. This is key to mitigate the major threats to their supply chain and the one of their downstream consumers. The proposed activities contribute to the improvement and maintenance of Eclipse Foundation projects, especially with regard to security and resilience. Th Eclipse-Project will mainly focus on two work packages. A first objective would be to have projects generate a Software Bill of Materials (SBOM) as part of their build pipelines. An SBOM is a list of all the software components, dependencies, and metadata associated with an application. A second objective would be to continue to improve the vulnerability management processes. The activities for this objective would be: - Implement a continuous vulnerability monitoring solution. This will help identify vulnerabilities in project dependencies as soon as they are discovered, even after the software has been released. - Educate the developers and maintainers on how to handle vulnerability reports from researchers. This includes understanding how to triage vulnerabilities, prioritize them, and remediate them effectively. - Invest in tooling to help manage and fix vulnerabilities. This could include a vulnerability scanner, a vulnerability management platform, or other tools that can help to automate the process of remediating vulnerabilities.

Analyse: Zuschlagskriterien, Eignung, Checkliste — mit Konto

Mit einem Konto liest Tender Automation die Vergabeunterlagen dieses Verfahrens und erstellt daraus eine Analyse: Zuschlagskriterien mit Gewichtung, Eignungsanforderungen, Zeitplan und eine Checkliste der einzureichenden Unterlagen.

Analyse ansehen

Angaben aus der Bekanntmachung

Auftraggeber
SPRIND GmbH
Ort
Leipzig
CPV
73110000 — Forschungsdienste
Weitere: 73300000
Verfahrensart
Verhandlungsverfahren ohne Aufruf zum Wettbewerb
Veröffentlicht
09.08.2024
Kennung
f228b92a-033a-42c5-a595-e13b0db74f1a
Quelle
TED (EU-Amtsblatt)

Lose

Zum Vergabeportal

Verbindlich sind allein die Angaben auf dem Vergabeportal. Stand dieser Seite: 09.08.2024, 00:00.