Overview
- IBM and Red Hat announced Project Lightwell on Thursday as a $5 billion program to build a trusted enterprise clearinghouse for open-source security.
- The clearinghouse will use advanced AI to find, triage, validate, and test vulnerabilities and fixes so enterprises can receive production-ready patches.
- IBM said it will field more than 20,000 engineers to work alongside AI tools on upstream maintenance, patch development, dependency hardening, and release engineering.
- The service has been piloted with major banks and payments firms and will be offered as a subscription expected to launch commercially within about 30 days.
- The effort responds to recent AI-driven scans that flagged thousands of open-source flaws and aims to let companies report bugs confidentially while sharing validated fixes back to upstream projects; IBM also cited its use of more than 62,000 open-source packages to show the scale of the challenge.