TECH & AI
When 20,000 engineers back your idea, you must be onto something good.
In this case, those engineers belong to Red Hat and IBM, who recently committed US $ 5bn to open source security. That investment has now produced Lightwell, a platform designed to tackle the 581 vulnerabilities lurking in the average enterprise codebase.
Lightwell introduces two offerings targeting enterprise software development teams. Lightwell Network and Lightwell Clearinghouse Premier combine AI-driven automation with human engineering expertise to identify, validate and remediate vulnerabilities in open source dependencies.
The platform breaks the dependency remediation deadlock by automating backported fixes for long-lived production software versions, reducing breaking changes and the extensive regression testing that typically paralyses teams forced into major upstream upgrades. Enterprises gain immediate access to a catalogue of more than 6,500 remediated, digitally signed and certified application dependencies across ecosystems.
Normally, when a security flaw is found in software like Python or Java, companies are trapped between three bad choices.
“ The first option is to force a major upgrade,” explains Brian Gracely, Senior Director of Red Hat Portfolio Strategy.“ If you upgrade to the newest version of the software, it fixes the security flaw but it often breaks testing code and forces a bunch of testing. cybermagazine. com 83