惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
博客园 - Franky
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
月光博客
月光博客
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
Microsoft Security Blog
Microsoft Security Blog
Last Week in AI
Last Week in AI
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
爱范儿
爱范儿
J
Java Code Geeks
博客园 - 叶小钗
Engineering at Meta
Engineering at Meta
阮一峰的网络日志
阮一峰的网络日志

Aikido Security's Blog

GlassWorm goes native: New Zig dropper infects every IDE on your machine Aikido Attack finds multiple 0-days in Hoppscotch The cybersecurity doomerism around Mythos doesn't match what we see on the ground axios compromised on npm: maintainer account hijacked, RAT deployed Popular telnyx package compromised on PyPI by TeamPCP Aikido × Lovable: Vibe, Fix, Ship CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran TeamPCP deploys CanisterWorm on NPM following Trivy compromise Security testing is validating software that no longer exists Aikido Recognized by Frost & Sullivan with the 2026 Customer Value Leadership Award in ASPM GlassWorm Hides a RAT Inside a Malicious Chrome Extension fast-draft Open VSX Extension Compromised by BlokTrooper Glassworm Strikes Popular React Native Phone Number Packages Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories How Security Teams Fight Back Against AI-Powered Hackers Introducing Betterleaks, an open source secrets scanner by the author of Gitleaks Trump’s 2026 cybersecurity strategy: From compliance to consequence How does AI pentesting work with compliance? What continuous pentesting actually requires Rare Not Random: Using Token Efficiency for Secrets Scanning Persistent XSS/RCE using WebSockets in Storybook’s dev server Why Determinism Is Still a Necessity in Security WAF vs. RASP vs. ADR Introducing Aikido Infinite: A new model of self-securing software How Aikido secures AI pentesting agents by design Astro Full-Read SSRF via Host Header Injection How to Get Your Board to Care About Security (Before a Breach Forces the Issue) What is Slopsquatting? The AI Package Hallucination Attack Already Happening SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel Top 6 Wiz Code Alternatives
Securing Legacy Dependencies with Aikido and TuxCare
Trusha Sharma · 2025-07-15 · via Aikido Security's Blog

TL;DR We’ve partnered with TuxCare so you can fix vulnerabilities in legacy dependencies instantly, without rewrites or risky upgrades. Stay secure, compliant, and keep building without trade-offs. Read on for the full launch, or check out our docs to go deeper.

As engineering teams scale, managing vulnerabilities in third-party libraries becomes one of the biggest blockers to shipping safely and quickly. When popular open-source packages reach end-of-life (EOL), security and development teams often find themselves at odds: security teams push for immediate upgrades to address CVEs, while developers face breaking changes that can slow delivery for weeks or months.

Upgrading core dependencies isn’t just about version bumps; it can mean deep refactors, application rewrites, and extensive retesting. For many organizations, this trade-off between security and velocity creates operational gridlock.

The power of the Aikido and TuxCare partnership

To solve this, Aikido and TuxCare have joined forces to offer Extended Lifecycle Support (ELS) directly through Aikido’s Autofix. This partnership combines Aikido’s automated remediation workflows with TuxCare’s expertise in providing hardened, continuously patched packages for EOL libraries.

TuxCare has already resolved over 5,000 CVEs in open-source software, making them a trusted partner in post-EOL security. By integrating ELS packages directly into Autofix, Aikido helps teams secure legacy dependencies and keep moving forward without big version changes or disruptive rewrites.

How it works

When Aikido scans your application, it identifies outdated dependencies and surfaces known vulnerabilities. Instead of requiring you to upgrade to the latest (and potentially breaking) major version, Aikido now suggests a secure ELS package maintained by TuxCare.

These ELS packages are drop-in replacements. For example, teams using the unmaintained v1 of SnakeYAML can move to 1.33.tuxcare.1 to patch critical CVEs without migrating to 2.x. The same principle applies to other widely used packages like log4j 1.x, which has been out of maintenance since 2015 but remains common in enterprise codebases.

Aikido Autofix generates a ready-to-merge pull request that updates your dependency to the ELS version and includes any repository configuration needed. Teams can resolve security issues immediately, without introducing instability or delaying feature work.

Removing friction between security and dev teams

Bridging the gap between security and development requires solutions that respect both priorities: strong security posture and continuous delivery. Aikido and TuxCare’s integrated approach enables teams to:

  • Avoid disruptive upgrades: Secure dependencies without major refactors or breaking changes.
  • Accelerate CVE resolution: Patch vulnerabilities in days instead of weeks or months.
  • Maintain compliance: Address EOL package risks to meet regulatory requirements and pass audits.
  • Reduce engineering overhead: Free up team capacity to focus on product improvements, not firefighting dependency updates.

Sample use case: Securing Java projects with ELS

In a typical Java project, updating a critical dependency like SnakeYAML or log4j to a new major version can take weeks of engineering time, extensive testing, and risky production deployments.

With ELS, teams can adopt a hardened version (for example, log4j 1.2.17.tuxcare.1) that patches known CVEs, all without changing application logic. This means security issues are resolved faster, engineering effort is minimized, and releases stay on track.

The future of secure, legacy code

At Aikido, we believe developers shouldn’t have to choose between speed and security. Our partnership with TuxCare is a major step forward in making post-EOL security practical and scalable, so you can stay focused on building.

This is just the start. ELS support is currently live for Java, with additional languages including JavaScript, Python, .NET, PHP, and Ruby coming soon.

Learn more about how Aikido and TuxCare can help you secure your legacy code without slowing down your roadmap. Get started here →