Vulnerabilità ed exploit
IBM e Red Hat stanno cercando di attrarre il lavoro di riparazione upstream verso una clearinghouse sostenuta da abbonamenti. La rottura pratica è che la validazione delle fix, l’ingegneria di release e la delivery per le dipendenze open-source core potrebbero non dipendere più solo dai maintainers volontari o dal ritmo del progetto originale.
4 fonti · 28 mag
CSO Online
IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise
The $5 billion Project Lightwell initiative combines AI systems with 20,000 engineers to deliver validated fixes directly into enterprise software supply chains without disruptive upgrades.
originaleHelp Net Security
IBM and Red Hat are betting $5 billion that open source needs a security guard - Help Net Security
IBM and Red Hat announced Project Lightwell, a $5 billion commitment backed by new frontier AI capabilities.
originaleSecurityWeek
IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell”
Project Lightwell is designed to fix vulnerabilities without breaking what is already in production.
originalePart of the PlainSec briefing for 2026-05-28
Every edition of this story: Le fix Open Source si spostano verso gatekeeper a pagamento