IBM and Red Hat have announced the launch of an initiative Project Lightwell, under which the companies plan to invest 5 billion dollars to protect open source software and software supply chains. The project is presented as a "trusted coordination center" for identifying, validating, and fixing vulnerabilities in open source components used by enterprise clients.
Essence Project Lightwell — to extend Red Hat's familiar model of supporting enterprise open source beyond its own products. Previously, the company tested, signed, delivered, and sent upstream fixes primarily for components of its platforms, but now this approach is intended to be applied to a broader range of dependencies: independent libraries, language toolchains, AI frameworks, and streaming data platforms.
According to IBM and Red Hat, enterprise clients will be able to report security issues found in specific versions of the software used, receive validated fixes, and integrate them into their existing build and supply chains. Red Hat specifically states that customers will be able to direct their build tools, including Artifactory, Nexus, or Maven, to a secure Red Hat registry; after that, the company will scan, backport, test, sign, and deliver the corrected artifacts for pinned package versions.
Project Lightwell will be offered as a commercial subscription. Reuters reports, citing IBM Software Senior Vice President Rob Thomas, noting that the service is expected to become commercially available "within the next 30 days," and the price will likely depend on the number of packages used. According to IBM, clients will be able to receive a sort of confirmation from the clearinghouse that their open source components are safe for use in production.
The project claims participation from more than 20,000 engineers from IBM and Red Hat, as well as the application of AI for mass vulnerability analysis, sorting, prioritization, and verification of fixes. At the same time, Red Hat emphasizes that AI is viewed as a tool to accelerate the initial processing of data, while critical decisions should remain with engineers who understand the context of upstream development, backend compatibility, and responsible disclosure procedures.
The first participants of Project Lightwell were major financial organizations, including Bank of America, BNY, Citi, Goldman Sachs, JPMorgan Chase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa, and Wells Fargo. In these implementations, IBM and Red Hat plan to refine the processes of identifying, verifying, and addressing vulnerabilities in complex software supply chains.
IBM emphasizes the scale of the problem: the company itself uses over 62 thousand open source packages and declares deep expertise in more than 10 thousand of them. Among the areas where IBM and Red Hat have already accumulated expertise are Linux, Java, Kubernetes, Kafka, Ansible, Terraform, Flink, and Cassandra.
In fact, Project Lightwell appears to be an attempt to transform the maintenance and verification of open source dependencies into a standalone corporate product. A critical question for the community will be how quickly fixes will be pushed upstream rather than remaining within the paid IBM/Red Hat environment. In the official project description, the companies promise to deliver verified fixes to clients while also contributing patches to open projects through a responsible disclosure process.
Source: linux.org.ru
