惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
Vercel News
Vercel News
Microsoft Azure Blog
Microsoft Azure Blog
爱范儿
爱范儿
N
Netflix TechBlog - Medium
Google DeepMind News
Google DeepMind News
H
Help Net Security
罗磊的独立博客
The Cloudflare Blog
J
Java Code Geeks
博客园 - 叶小钗
I
InfoQ
B
Blog
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
月光博客
月光博客
博客园_首页
雷峰网
雷峰网
M
MIT News - Artificial intelligence
博客园 - 【当耐特】
美团技术团队
T
The Blog of Author Tim Ferriss
博客园 - 司徒正美

The Stack

How Lloyds has transformed its trusted critical data for AI Micron's revenue surges with no end to the memory shortage in sight Ubiquiti UniFi OS vulnerabilities exploited in the wild Mistral's new OCR 4 model shows size matters EU approves €76m in state aid for chip testing firm Even FedEx is a winner of the data centre boom Why AWS thinks AI coding assistants need a new place to run Why China is forging closer ties with open-source foundations China's CPU-only supercomputer tops power list Runtime: Why 'Bring-your-own-Cloud' is taking off; the TRAIT&R framework for agents, and... AWS adds yet another security tool to speed up patching Scattered Spider: UK teen pleads guilty to TfL attack OSS security finally gets a Magic Quadrant Places for People forking out £60m for new ERP system Google offers ATT&CK for bad AI, with surging cost forecast STACKUP: The Stack's weekly tech startups and funding wrap Bring Your Own Cloud: why more enterprises are buying in AWS takes NVIDIA "G7" Blackwell instances GA Runtime: Vercel sets up a new framework for agents, Databricks finds a new Genie, and… Borussia Dortmund's IT head has to sometimes think "outside of the box" Accenture stumbles after Middle East, AI, merger questions Cabinet Office offering £100k+ for AI "ambassador" Critical Splunk Enterprise vulnerability being exploited Accenture buys majority stake in OT security company Dragos npm's security rethink, Satya’s warning, a COBOL win, and... US spending billions to counter China's tech influence NatGeo Society CTO on migrating 15 years of video data to the cloud Alibaba opens French data centres in Europe cloud push SpaceX to take over Cursor in $60bn play for AI coding market Hosting firm Hetzner hikes prices sharply amid supply chain pain
Red Hat's $5 billion answer to Mythos: fix all the code
Phillip de Wet · 2026-06-16 · via The Stack

In late May, Red Hat and its parent IBM announced they would allocate $5 billion and 20,000 engineers to Project Ligthwell, "to help enterprises secure open source software" alongside a group of big-target financial services companies.

The project, which the companies describe as "a trusted enterprise clearinghouse" for open source code, is exactly what Red Hat has always done: backporting security patches and upstreaming them, securing customers first and improving the entire ecosystem over time.

Even the mechanism is similar. Project customers point their build tools to the Red Hat registry and Red Hat takes care of scanning, backports, and patching, plus managing the upstream contributions. 

See also: IBM muscles into OSS security space with $5 billion “Lightwell” project

But the project's plans to address the broader application landscape, including "independent libraries, language toolchains, AI frameworks, and data streaming platforms", is were it diverges from securing a discrete set of packages.

And that complicates matters – starting with who gets to decide what is covered.

When it expands beyond the early adopters, Red Hat chief product officer Ashesh Badani told The Stack Lightwell will likely have two contract tiers. Those who only need the patches will be able to choose a "read-only mode", with a premium option for those who want to be involved in determining which packages Lightwell will include.

Get the full story: Subscribe for free

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

Subscribe now