IBM and Red Hat announced a $5 billion programme on 28 May called Project Lightwell, aimed at a problem most people never see and almost every large company has: the open source software buried deep in their systems is full of holes nobody has the time to fix. More than 90 percent of Fortune 500 companies rely on open source code, according to the joint announcement, and much of it is maintained by volunteers or no one at all.
The plan is to build what the companies call a trusted clearinghouse: a central security layer staffed by more than 20,000 engineers and backed by frontier AI models that scan open source projects, find the serious flaws, write the fixes, and validate them before they reach customers. Enterprises would subscribe and pull verified patches straight into their own software supply chains, as SiliconANGLE described it.
Why now
The timing is not an accident. Anthropic recently reported that its Mythos preview model identified close to 3,900 high or critical-severity vulnerabilities in open source software on its own. That figure cuts both ways. The same capability that lets a model run a multi-step attack in a lab can also be pointed at finding and sealing the gaps first. Project Lightwell is essentially a bet that defenders can industrialise that second use before attackers industrialise the first.
The early adopter list tells you who is most nervous about this. IBM and Red Hat say they are already working with Bank of America, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Visa and Wells Fargo, among others, according to InfoWorld. Banks have the most to lose from a supply-chain breach and the budgets to pay for insurance against one.
The question worth asking
There is something a little uncomfortable about a commercial clearinghouse sitting between volunteer-maintained software and the companies that profit from it. Open source has always run on goodwill. A paid security layer on top of it could help fund that work, or it could quietly turn a public commons into a product. The press release does not say how much of the $5 billion, if any, flows back to the maintainers whose code makes the whole thing possible.
For now the promise is straightforward and genuinely useful: find the dangerous bugs at machine speed, fix them properly, and get the fixes to the firms that need them. Whether it strengthens the open source ecosystem or just monetises its weak points is the part worth watching.
Sources
- i. newsroom.ibm.com
- ii. www.redhat.com
- iii. siliconangle.com
- iv. www.infoworld.com
- v. devops.com
Commentarii · 0