Open-Source Supply Chains: Fixing Them Is the Real Challenge

IBM and Red Hat announce that Lightwell has identified and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries.

Yet, no library is named, no CVE is cited, and no breakdown by severity is provided. It is impossible at this stage to verify the figure, nor for a CIO to determine whether it affects their organization.

The patches were developed and then backported, meaning they were integrated into older versions already deployed in production.

Launched last spring, Lightwell is a program designed to redefine the future of open-source software and to secure corporate software supply chains in the era of AI.

From Detection to Remediation: The Imbalance

Past years have seen supply-chain security built around visibility—inventorying components, spotting vulnerabilities, and prioritizing risks. AI is unsettled this balance by accelerating flaw discovery.

See also: Project Lightwell: IBM and Red Hat invest $5 billion to secure the software supply chain

According to Red Hat, aging code or code once deemed stable is not immune: it only takes an AI agent spotting a flaw, even a minor one, to ignite a multi-step attack.

On the other hand, Anthropic’s Glasswing program offers another scale of magnitude. Between April and July 2026, its partners identified at least 129,000 verified vulnerabilities, more than 33,000 of which were rated critical or high. Anthropic regards these numbers as significantly underestimating the true figure.

These two numbers measure different things: Glasswing catalogs vulnerabilities found across a wide array of software, while Lightwell tracks flaws fixed in Java libraries. It is not to say that Lightwell has addressed only 0.3% of the problem, but to illustrate that discovery proceeds far faster than remediation.

Fixing Is Harder Than Finding

Fixing a vulnerability in production is not as simple as installing the latest version. An upgrade can alter APIs, break compatibility, introduce regressions, or trigger re-certifications. Some applications rely on versions that upstream maintenance no longer supports.

The remedy is backporting. In practice, this means writing the fix for the version actually in deployment and then porting it back to an older branch. That requires an understanding of the code, verification that the fix works, careful elimination of side effects, testing, and distribution. It is not an automated process.

For Gunnar Hellekson, Red Hat, bug detection is only half the battle. The other half is ensuring customers do not have to choose between security and availability. It is this slow, costly engineering that Lightwell seeks to industrialize.

A Maintenance Service Offered on a Subscription Basis

With an announced investment of $5 billion and more than 20,000 engineers, augmented by AI tools, Lightwell combines the open-source engineering prowess of the two organizations. In July, they unveiled an initial catalog of more than 6,500 remediated dependencies, digitally signed and certified for Java and Python ecosystems, with the ambition of expanding from thousands to potentially millions of packages.

The Clearinghouse adds an extra step. Rather than simply pulling from a catalog, a company can submit its own vulnerabilities or dependencies for review and remediation tailored to the older versions still in use.

The offering is sold on an annual subscription basis in two tiers. Lightwell Network provides access to verified fixes and patched software to be integrated into existing workflows. Lightwell Clearinghouse offers bespoke handling of submitted dependencies. An additional program provides free access for certain universities, NGOs, and American think tanks.

The positioning is that of an maintenance infrastructure where patches are distributed through secure repositories. Companies retain their scanners, repositories, pipelines, and testing processes. According to IBM and Red Hat, nothing must be replaced. The business model embraces sharing a high engineering cost and selling it to enterprises that cannot manage it in-house.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.