Open-source security is a mess - IBM and Red Hat bet $5 billion and 20,000 engineers can fix it
Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
- Lightwell is a huge effort to safeguard open-source software.
- IBM and Red Hat are investing in this massive security initiative.
- We don't yet know how this subscription-based service will work.
AI is a mixed blessing for open-source software. On the one hand, AI can help developers program faster and find bugs more quickly. On the other hand, maintainers are being overwhelmed by the sheer volume of potentially serious bug reports.
As Daniel Steinberg, founder and maintainer of the popular open-source data transfer program cURL, recently said, "The rate of incoming security reports is four to five times higher than it was in 2024and double the speed of 2025." For the first time, he confessed, "I work more than I've done before, but the flood keeps coming." Steinberg is on the verge of burning out....
Copyright of this story solely belongs to zdnet.com. To see the full text click HERE