IBM and Red Hat have launched and expanded Lightwell, an AI-assisted open source security initiative aimed at helping enterprises secure software supply chains as AI-generated and AI-assisted code becomes more common. The platform combines software signing, provenance generation, artifact verification, policy validation, lifecycle management, and remediation services so organizations can verify how software was built, whether artifacts were altered, and whether releases comply with internal security requirements. IBM and Red Hat position Lightwell as a commercially supported implementation of supply-chain security practices including Sigstore, in-toto, SLSA, and SBOM-driven workflows.
The rollout includes Lightwell Network, which provides signed binaries, source code, compliance artifacts, and SBOMs, and Lightwell Clearinghouse Premier, initially offered in limited availability for the financial services sector with embargoed vulnerability coordination and version-targeted remediation. The companies said the services are designed to identify, validate, and remediate open source vulnerabilities at scale, including backporting critical fixes to long-lived production versions instead of requiring major upstream upgrades, as vendors race to counter AI-enabled attacks and strengthen trust in open source development.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
IBM and Red Hat announced an expansion of Lightwell with new commercial offerings focused on trusted and verifiable software supply chains. The expanded platform adds capabilities such as signing, provenance generation, artifact verification, policy validation, and lifecycle management, building on standards including Sigstore, in-toto, SLSA, and SBOM practices.
IBM and Red Hat announced Lightwell as an AI-assisted initiative to detect, validate, and remediate vulnerabilities in open source software at scale. The launch materialized as two offerings: Lightwell Network, broadly available, and Lightwell Clearinghouse Premier, entering limited availability for the financial services sector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
infoq.com
Open sourcezdnet.fr
Open sourceslsa.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.