Enter your email address below and subscribe to our newsletter

IBM and Red Hat launch $5B open-source security initiative

Share your love

  • IBM 5.05% and Red Hat announced Project Lightwell, a $5 billion initiative creating a clearinghouse for open-source software security.prnewswire
  • The subscription service, launching within 30 days, lets companies report flaws, receive AI-validated fixes, and integrate patches into production systems.channelnewsasia
  • Early pilots involved Bank of America 0.58%, JPMorgan Chase 2.47%, and Visa 0.95% to test vulnerability detection at scale.channelnewsasia

IBM and Red Hat Launch $5 Billion Project Lightwell to Secure Open Source Software

IBM and Red Hat on Thursday announced Project Lightwell, a $5 billion initiative deploying more than 20,000 engineers and AI-driven tools to help enterprises secure the open source software that underpins most corporate technology systems.prnewswire

A Clearinghouse for Open Source Security

Project Lightwell establishes what IBM describes as a “trusted enterprise clearinghouse” — a central hub where companies can confidentially report security flaws, receive AI-validated fixes, and share those patches with the broader open source community. The service uses advanced AI capabilities to identify and test fixes across large volumes of open source code, offering what Rob Thomas, IBM’s senior vice president of software, called a “stamp of approval from the clearinghouse that their open source is safe to use in production”.channelnewsasia

The offering will be delivered through commercial subscriptions, likely priced by the number of packages used, and is set to launch within 30 days, Thomas told Reuters. It covers the full software lifecycle, from upstream development through production environments, allowing businesses to plug vetted security patches directly into their existing software supply chains.prnewswire

Financial Sector Among Early Adopters

IBM and Red Hat have already piloted Project Lightwell with several major financial institutions, including Bank of America, JPMorgan Chase, and Visa, to refine how the system detects and resolves vulnerabilities across complex enterprise software.channelnewsasia

The initiative addresses a growing tension in enterprise computing: open source code is freely available and powers the vast majority of corporate technology systems, but its ubiquity has made it a prime target for hackers — particularly as AI lowers the barrier for attackers to find and exploit security flaws.channelnewsasia

Broader Industry Context

Project Lightwell represents a substantial escalation in spending on open source security. In March, the Linux Foundation announced $12.5 million in grants from Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft, and OpenAI to strengthen open source security through its Alpha-Omega and OpenSSF initiatives. IBM’s $5 billion commitment dwarfs those earlier efforts and expands Red Hat’s traditional approach of securing software within its own platforms to cover a broader ecosystem of independent open source components, including libraries and AI frameworks.openssf

Leave a Reply

Your email address will not be published. Required fields are marked *

Stay informed and not overwhelmed, subscribe now!