IBM, Red Hat Commit $5B to Open-Source Security
IBM and Red Hat have launched Project Lightwell, a $5 billion initiative backed by over 20,000 engineers aimed at securing open-source software across the enterprise ecosystem. The program uses AI to find vulnerabilities and backport patches to legacy versions, eliminating the need for costly application upgrades.
Project Lightwell extends Red Hat's existing security work beyond its own product portfolio to the broader open-source landscape. IBM will offer access via subscriptions and establish a trusted intermediary framework to share vulnerability disclosures with open-source project maintainers. The initiative poses direct competition to supply chain security firms like Chainguard and Socket.
