IBM and Red Hat report hundreds of open source fixes with Lightwell Clearinghouse scheme
Lightwell Clearinghouse is now generally available, allowing firms to request priority review and remediations for open source software
IBM and Red Hat have fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through their Lightwell Clearinghouse initiative.
Announced earlier this year with a $5 billion investment and more than 20,000 engineers, Lightwell Clearinghouse lets enterprise customers submit open source software dependencies for priority review and fixes.
"For over two decades, Red Hat has backported security patches across thousands of packages," said Matt Hicks, president and CEO of Red Hat.
"Lightwell scales this exact model across a wider scope of open source ecosystems. We are applying the same discipline, upstream commitment, and engineering rigor across all active application layers."
Since the initial Lightwell launch, the duo said they have uncovered, remediated, and backported fixes for hundreds of previously unknown bugs in widely deployed, production-grade software.
"Finding and neutralizing 400-plus novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started," said Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat.
IBM and Red Hat’s combined capabilities
Lightwell is designed to make the most of the two firms' open source engineering expertise, together with Red Hat’s secure software supply chain capabilities, build infrastructure and open source community relationships.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
The project uses AI-assisted engineering workflows, although AI-generated patches aren't automatically distributed to customers but are first tested and validated by humans.
It develops version-specific fixes for open source application dependencies in production systems that are delivered through secured repositories that connect with customers’ existing IT processes.
This, the two firms said, allows organizations to address difficult or previously unknown vulnerabilities without needing to replace their current security scanners, software repositories, development pipelines or testing processes.
Through Lightwell Network, IT teams can access verified patches, bring remediated software into their existing workflows and establish an ongoing process for addressing vulnerabilities.
Broader open source gains
The fixes that are developed through Lightwell are contributed to upstream open source projects under responsible disclosure protocols, said the firms, maintaining embargo protections for Lightwell Clearinghouse participants.
Lightwell Network launched commercially in July, with more than 6,500 patched and digitally signed software dependencies for Java, Python, and other languages. Universities, non-governmental organizations and think tanks were given free access in August, and it's now been made generally available.
"AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together," said Hellekson.
"Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime."
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
New Google Gemini setting could give AI tool broad access to users' MacsNews A new permission would allow an AI agent to access files and carry out actions without specific permission every time
-
Finance teams are wasting a quarter of their week checking AI slopNews AI adoption is high in financial processes, but accuracy and accountability remain challenges
-
‘This pause is due to a significant rise in automated submissions, the vast majority of which are not valid’: Google pauses open source bug bounty scheme over AI slop submissionsNews The Google open source scheme is the latest bug bounty to fall victim to AI-generated submissions
-
Huawei reiterates its commitment to open source standards at Connect 2026News The Chinese IT giant is the latest to declare open source a key element of AI
-
Red Hat launches new open source project to drive AI governanceNews The asago open source project will allow enterprises to automate compliance processes and bolster security
-
Amazon targets agent safety gains with investment in team behind Lean programming languageNews The tech giant hopes support for the open source programming language could drive AI agent safety improvements
-
‘These Chinese models are excellent’: Nvidia CEO Jensen Huang hails powerful new Chinese AI models like Kimi K3 – and says don’t be put off by security ‘misconceptions’News As powerful new AI models like Kimi K3 hit the market, Huang says competition will be a positive for the global industry
-
IBM targets AI cost optimization with updates to Bob developer toolNews New features for IBM Bob aim to provide greater oversight of AI usage and improve resource allocation
-
Apple is speeding up software patching due to AI security concerns – here’s what you need to knowNews Apple is speeding up its software patching processes amid rising concerns that AI is helping hackers to spot and exploit flaws at a far quicker pace.
-
The UK is betting big on the power of open source AINews The government wants to encourage open source developers to help improve public services