Broadcom has resolved to make the security of popular open source code its own area of responsibility. The company has launched TrueSource, a commercial program that spans Spring, thousands of Java libraries, the Python and Node.js ecosystems, container images, and several widely used databases.
The Foundation of the Program
The new program is built upon TrueSource. Broadcom promises to select, build, and verify software components itself, and to remedy any problems found together with the maintainers of open projects. For Spring and RabbitMQ, the company acts as maintainer in its own right, so it can directly control the release of fixes. For other projects, Broadcom intends to contribute changes upstream to the source-code developers, preserving the upstream projects as the primary source of verified versions.
Trusted Artifacts Beyond Spring
TrueSource Trusted Artifacts extends this approach far beyond Spring. Broadcom will prepare isolated, verifiable builds of Java, Python, and Node.js libraries that conform to the third level of SLSA. Such an approach helps protect the software supply chain and confirm the provenance of a finished component, rather than simply trusting a package from an external repository.
In Java alone, Broadcom intends to support more than 5,000 verified and signed libraries, including the dependencies of Apache Tomcat and Kotlin that use supported versions of Spring Boot. The subscription will also include the Bitnami Secure Images catalog, with hardened container images for hundreds of popular open packages.
Data Services
A separate part of TrueSource bears the name Data Services. Broadcom has included PostgreSQL, RabbitMQ, MySQL, and Valkey within it, along with the necessary extensions, Kubernetes operators, and Helm Charts. The company will verify such components, assist with deployment, and show customers the security posture of the stack they use.
Automated Remediation
Broadcom will also automate the search for problems in customer repositories. The system is meant to assess the impact of new releases, propose the least risky remediation path, and automatically create a pull request. For vulnerabilities, the company will be able to issue standalone fixes without the other changes of a new version, so that organizations need not undertake a full product upgrade merely to close a single issue.
Early Access to Fixes
TrueSource customers will be able to disclose to Broadcom, in advance, information about not-yet-public vulnerabilities and receive fixes before public disclosure. Critical-infrastructure organizations are promised dedicated access to information about fixes and to risk-mitigation guidance.
A Technical and Commercial Play
For Broadcom, this move addresses a technical and a commercial objective at once. Spring has long belonged to the VMware Tanzu portfolio, and enterprise applications depend on an enormous number of third-party libraries whose quality the platform vendor does not directly control. TrueSource extends the boundaries of support from Broadcom’s own product to a substantial part of the surrounding open source ecosystem, and in effect sells companies verified provenance, maintenance, and accountability for code that previously had to be taken “as is.”
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.