IBM and Red Hat Commit $5 Billion to Project Lightwell, Aiming to Fix Open-Source Security at Scale
Overwhelmed by an AI‑driven flood of security reports, open‑source maintainers are burning out. In response, IBM and Red Hat have launched Project Lightwell — a $5 billion, 20,000‑engineer initiative using AI to find and fix vulnerabilities across open‑source software. Lightwell will act as a trusted intermediary: enterprises feed information about the OSS they use, Lightwell engineers use AI to hunt for flaws and generate candidate patches, then work with upstream maintainers to merge fixes. Starting with the Maven/Java ecosystem, it will expand to PyPI, npm, Go, and others. The service will be offered via commercial subscriptions (launching within 30 days) that provide vetted fixes and a “stamp of approval” for production use. Critics question what exactly customers pay for if patches go upstream, and whether Lightwell becomes a de facto gatekeeper. No clear answers yet.
Comments
Post a Comment