Upgrade to SI Premium - Free Trial

IBM and Red Hat launch Lightwell open source security platform

July 8, 2026 9:02 AM

IBM (NYSE: IBM) and Red Hat have commercially launched Lightwell, a platform designed to automate vulnerability remediation in open source software, the companies announced.

The launch includes two offerings. Lightwell Network is generally available and provides access to a catalog of more than 6,500 remediated, digitally signed, and certified application-layer dependencies across ecosystems including Java and Python. Lightwell Clearinghouse Premier has entered a limited-availability phase, functioning as an intermediary for patch embargoes and industry threat coordination, initially limited to the financial services sector. Red Hat and IBM said they plan to expand Clearinghouse Premier to government, healthcare, and telecommunications in future phases.

The launch follows a $5 billion commitment to open source security that IBM and Red Hat announced in May 2026. The companies said the platform is backed by more than 20,000 engineers and uses a generative AI-powered remediation engine that combines AI models with human engineering to identify and address vulnerabilities.

Lightwell uses a backporting approach to apply fixes to specific production software versions, aiming to avoid disruptive upstream upgrades. Red Hat and IBM said they expect the catalog of remediated packages to scale from thousands to millions.

Technology partners collaborating on Lightwell include Amazon Web Services, AMD, F5, GitLab, Intel, JFrog, Microsoft, Nvidia, Palo Alto Networks, and ServiceNow. Deployment and consulting partners include Accenture, Atos, Cognizant, Deloitte, IBM Consulting, Infosys, Kyndryl, NTT DATA, Tata Consultancy Services, and others.

"Lightwell represents a fundamental structural shift in how we secure all enterprise software," said Matt Hicks, President and CEO of Red Hat. "By pairing automated remediation with our deep engineering heritage, we aim to deliver the trusted infrastructure required to consume open source reliably, sustainably, and at AI speeds."

According to data cited in the press release, open source comprises up to 90% of enterprise codebases, with 9.8 trillion downloads recorded in 2025, and enterprise codebases averaging 581 vulnerabilities.

Categories

Corporate News

Next Articles