Red Hat’s open-source security initiative Lightwell has remediated over 400 novel vulnerabilities across foundational Java libraries since the project's launch in June.
This comes as the company announced at the general availability of the Lightwell Clearinghouse following a pilot testing phase.
The company, alongside parent IBM, was among the first to respond to the influx of AI-powered vulnerability reporting, creating processes to validate and address genuine flaws while reducing the burden of noisy or inaccurate submissions on open-source maintainers.
The initiative was backed by a $5bn investment from IBM and Red Hat, 20,000 in-house engineers dedicated to it as well as “early adopters” from the financial sector, including Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa and Wells Fargo.
Gunnar Hellekson, VP at Red Hat and general manager of Lightwell, said the emergence of AI agents “shifted the threat landscape overnight, exploiting old dependencies at machine speed.”
“They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together,” he added. This ultimately resulted in the pursuit of the Lightwell initiative.
Read now: Linux Foundation's Akrites to Go Live in September
Lightwell: An Open Source Vulnerability Clearinghouse
The project’s mission is to meet Red Hat’s enterprise customer needs where open-source package versions are at risk today, according to the company.
Hellekson noted, “Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime.”
In July 2026, IBM and Red Hat unveiled two product offerings, Lightwell Network and Lightwell Clearinghouse Premier.
The former has been available from launch and provides immediate access to a continuous stream of digitally signed binaries, source code and comprehensive compliance artifacts, including complete software bills of materials (SBOMs).
Lightwell Clearinghouse Premier is a more advanced offering designed for select enterprise customers running pinned versions in production who need targeted remediation and backports.
By joining this premium offering, Red Hat customers can submit specific open source vulnerabilities to IBM and Red Hat for priority review, remediation and fixes that can be applied to older software versions still in use.
In practice the Lightwell Clearinghouse Premier workflow as follows:
- A customer reports vulnerability tied to specific package or version
- Red Hat triages it and determines severity, applicability and remediation
- Red Hat develops a patch/backport appropriate for that exact supported version
- Upstream coordination ensures the fix is technically acceptable and aligned with the project
- Red Hat builds the corrected package on its own infrastructure
- The output is signed and attested, giving the customer provenance and assurance about what was built
- The customer deploys the resulting binary rather than having to independently reproduce the entire remediation and validation process
Both products are built around the Lightwell Clearinghouse, a vulnerability management engine designed to develop version-specific fixes for open-source application dependencies in production systems.
“Delivered through secured repositories that integrate directly into existing customer IT workflows,” said Red Hat in a public statement.
“This helps organisations address difficult and/or novel vulnerabilities without replacing their current scanners, repositories, CI/CD pipelines or validation processes.”
Image credits: Bryan Regan / Shutterstock.com
Read more: How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
