// ITS FOSS — LINUX & OPEN SOURCE
Red Hat's Lightwell Doesn't Wait for Upstream Maintainers to Act
Lightwell is Red Hat and IBM's response to a specific problem in enterprise open source security. Vulnerabilities sit in production library versions that upstream maintainers haven't patched and, in some cases, won't.
More than 90% of enterprise application code traces back to open source or third-party libraries, per figures Red Hat cites, and a typical enterprise codebase carries over 500 known vulnerabilities at any given time.
They say that attacks on known vulnerabilities arrive, on average, a week before any patch exists.
Lightwell's approach is to bypass that timeline. Rather than waiting for upstream maintainers to push fixes to the library versions enterprises are actually running, it backports those fixes directly, delivering them through secure package repositories.
Red Hat reached out recently to share how far it has come.
To date, Lightwell has already managed to clear 400 previously unknown vulnerabilities across foundational Java libraries, going beyond reported CVEs and contributing fixes upstream in line with responsible disclosure protocols.
The primary target so far has been organizations running Java environments with pinned dependency versions that can't be safely updated. Lightwell patches those in place, leaving the pinned version intact.
Coverage is also set to expand beyond Java, with Python, JavaScript, and .NET on the roadmap. Each will follow the same approach, with fixes backported to the versions already in production and applicable patches being contributed upstream.
Then there's Clearinghouse Premier, which has so far operated on restrictive terms. Before today, it was reserved for a pre-selected group of organizations in critical infrastructure sectors.
That restriction is now lifted, as it has reached general availability, which means any enterprise can sign up for Clearinghouse directly without waiting on an infrastructure designation to clear access.