Vulnerabilità · 125 giorni fa
IBM e Red Hat stanno cercando di attrarre il lavoro di riparazione upstream verso una clearinghouse sostenuta da abbonamenti. La rottura pratica è che la validazione delle fix, l’ingegneria di release e la delivery per le dipendenze open-source core potrebbero non dipendere più solo dai maintainers volontari o dal ritmo del progetto originale.
4 fonti che coprono questa storia
The $5 billion Project Lightwell initiative combines AI systems with 20,000 engineers to deliver validated fixes directly into enterprise software supply chains without disruptive upgrades.
IBM and Red Hat are betting $5 billion that open source needs a security guard - Help Net Security
IBM and Red Hat announced Project Lightwell, a $5 billion commitment backed by new frontier AI capabilities.
IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell”
Project Lightwell is designed to fix vulnerabilities without breaking what is already in production.
IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities
The tech giant’s project could make it easier for businesses to safely use open-source packages.
Part of the PlainSec briefing for 2026-05-28