IBM and Red Hat Commit $5 Billion to Redefine the Future of Open Source in the AI Era
Project Lightwell establishes a trusted enterprise clearinghouse for open source software with a new AI-driven model for securing the software supply chain
Project Lightwell will establish a trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale. The clearinghouse will serve as a security coordination layer, using advanced AI capabilities to validate and test fixes across an unprecedented volume of open source code. These capabilities will be offered through commercial subscriptions, allowing enterprises to integrate secure patches directly into their existing software supply chains with enterprise-grade validation and lifecycle management.
Open source software underpins modern enterprise infrastructure, with more than 90% of Fortune 500 companies relying on OSS 1. At the same time, advances in frontier AI are accelerating vulnerability discovery and exploitation. Anthropic recently reported that its Mythos Preview model identified nearly 3,900 high- or critical-severity vulnerabilities in open source software alone 2.
Project Lightwell builds on
"Open source is the backbone of today's digital economy and the foundation of modern AI, and we are at an inflection point in how it is built, secured, and scaled," said
Launching a Trusted Open Source Security Clearinghouse
Project Lightwell builds on
This approach directly addresses the operational vulnerabilities enterprises face when managing independent open source code on their own. Through the clearinghouse model, enterprise organizations can:
- Report and resolve vulnerabilities: Responsibly share sensitive security issues discovered in their active software versions within a trusted intermediary framework.
- Deploy validated patches: Receive patches optimized for production environments, spanning both Red Hat offerings and independent community code.
- Coordinate upstream disclosures: Share fixes upstream so that open source communities can include them in long-term maintenance.
This model allows enterprises to engage
AI-Powered Engineering at Global Scale
At a time when many technology companies are using AI to reduce technical headcount,
- Upstream maintenance alongside open source community leaders;
- High-volume, AI-assisted vulnerability review, triage, and prioritization;
- Secure patch development, dependency hardening, and release engineering.
Project Lightwell supports government priorities to secure digital infrastructure, protect critical systems, and strengthen the overall resilience of open source software ecosystems.
More information about Project Lightwell is available https://www.ibm.com/products/lightwell
|
1 |
Source: Worldmetrics; worldmetrics.org/opensource-statistics/ |
|
2 |
Source: |
About
Visit www.ibm.com for more information.
About Red Hat
Red Hat is the open hybrid cloud technology leader, delivering a trusted, consistent and comprehensive foundation for transformative IT innovation and AI applications. Its portfolio of cloud, developer, AI, Linux, automation and application platform technologies enables any application, anywhere--from the datacenter to the edge. As the world's leading provider of enterprise open source software solutions, Red Hat invests in open ecosystems and communities to solve tomorrow's IT challenges. Collaborating with partners and customers, Red Hat helps them build, connect, automate, secure and manage their IT environments, supported by consulting services and award-winning training and certification offerings.
Media Contacts
Red Hat
swonderl@redhat.com
Kate.lehman@ibm.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era-302783949.html
SOURCE