Tuesday, September 8, 2026
Open source security is in a dire state: IBM and Red Hat are betting that $5 billion and 20,000 engineers can fix it.
Cybersecurity - Trust - ResilienceOpen AI - Models - Data - Sovereign Ecosystems
A massive investment to address a problem that has become critical
Open source software security has become a major concern for businesses, as these components are now present across a large part of IT infrastructures and applications. But behind this widespread adoption lies a more worrying reality: open source projects have to manage an increasing number of vulnerabilities, often with limited human and financial resources.It is in this context that IBM and Red Hat are launching Lightwell, an initiative designed to strengthen the security of the open source ecosystem at scale. To achieve this, the two companies have announced an investment of up to $5 billion and plan to mobilize as many as 20,000 engineers.
AI at the heart of vulnerability detection and remediation
Lightwell plans to rely heavily on artificial intelligence to automate part of the work currently carried out by security teams and maintainers.The goal is in particular to analyze open source code and dependencies in order to:
- detect vulnerabilities;
- identify and prioritize the most significant risks;
- locate affected components;
- propose fixes;
- contribute to their development and backporting across different versions.
However, AI is not intended to operate on its own. The fixes generated or identified will be reviewed by human engineers before being proposed to the maintainers of the projects concerned. This combination of automation and human expertise should significantly speed up the vulnerability remediation process, while maintaining existing validation mechanisms.
Working with communities rather than replacing them
One of Lightwell’s key challenges is its relationship with open source communities. IBM and Red Hat want to work directly with maintainers and existing projects, rather than developing a completely independent security layer.
Engineers will therefore be able to contribute upstream and participate in the development of fixes. The goal is for these improvements to benefit the entire ecosystem, rather than only Lightwell’s customers.
This approach addresses a well-known challenge in open source: a small number of maintainers may be responsible for components used by thousands, or even millions, of organizations, while the resources available to these projects can remain very limited.
A first step focused on Java
Applications are open until October 2, 2026. They will be reviewed by a jury made up of recognized figures from the French Open Source ecosystem.
--
Whether you are a company, an organization, or the leader of an Open Source project, this anniversary edition is an opportunity to showcase your initiative and join the many stakeholders shaping the future of Free Software.
Join us on December 9 and 10, 2026, at Open Source Experience to discover the winners of the 10th edition of Acteurs du Libre.
Towards a new approach to supply chain security
With Lightwell, IBM and Red Hat are seeking to transform the way businesses approach open source security. It is no longer simply a matter of identifying a vulnerability when it is disclosed, but of monitoring the component throughout its entire lifecycle: detection, analysis, remediation, validation, and ongoing maintenance.
The project will be offered as a commercial subscription-based service, aimed at businesses looking to strengthen the security of their software supply chains.
Beyond the announced investment, the initiative therefore raises a broader question for the ecosystem: how can we sustainably fund and secure the open source components that today’s digital infrastructures depend on?
Lightwell’s approach, combining AI, human expertise, and collaboration with open source communities, could mark a new step forward in addressing these challenges.