For the more than 400 flaws, Lightwell engineers backported patches into the widely deployed versions of each library. Any fix that also applies upstream goes back to the open-source project under responsible disclosure protocols while Clearinghouse participants keep their embargo protections. Neither company has named the affected libraries.
Behind the fixes, engineers from both companies work alongside AI-assisted development workflows, and the builds run on Red Hat’s secure software supply chain infrastructure. Customers pull the patched packages from secured repositories that connect to their existing information technology processes, so nobody has to swap out security scanners or development pipelines to use them.
Putting those 20,000 developers to work! A whole or bugs being found and fixed everywhere. Related: “What Developer Teams Should Do Differently.”
Leave a Reply