[フレーム]
BT

InfoQ Software Architects' Newsletter

A monthly overview of things you need to know as an architect or aspiring architect.

View an example

We protect your privacy.

Facilitating the Spread of Knowledge and Innovation in Professional Software Development

Write for InfoQ

Unlock the full InfoQ experience

Unlock the full InfoQ experience by logging in! Stay updated with your favorite authors and topics, engage with content, and download exclusive resources.

Log In
or

Don't have an InfoQ account?

Register
  • Stay updated on topics and peers that matter to youReceive instant alerts on the latest insights and trends.
  • Quickly access free resources for continuous learningMinibooks, videos with transcripts, and training materials.
  • Save articles and read at anytimeBookmark articles to read whenever youre ready.

Topics

Choose your language

InfoQ Homepage News IBM and Red Hat Expand Lightwell to Strengthen Trust and Governance for AI-Era Open Source

IBM and Red Hat Expand Lightwell to Strengthen Trust and Governance for AI-Era Open Source

Listen to this article - 0:00
Audio ready to play
0:00
0:00

IBM and Red Hat have announced an expansion of Lightwell, introducing new commercial offerings designed to help organizations establish trusted, verifiable software supply chains for the age of AI-assisted software development. Building on the open-source Lightwell project, the new offerings aim to simplify software signing, provenance, artifact verification, and policy enforcement, enabling enterprises to ensure that both human- and AI-generated software can be trusted throughout the software delivery lifecycle.

The announcement reflects a growing shift in software security. As AI accelerates software creation, the challenge is no longer simply producing code faster, but proving where software originated, how it was built, whether it has been modified, and whether it complies with organizational security policies before reaching production. IBM argues that establishing a verifiable "trust infrastructure" will become a foundational capability as enterprises increasingly rely on AI-generated code, open-source components, and automated software supply chains.

Lightwell builds upon many of the security standards that have emerged over the past several years, including Sigstore, in-toto, SLSA (Supply-chain Levels for Software Artifacts), and software bill of materials (SBOM) initiatives. Rather than treating signing, provenance, and policy enforcement as independent activities, Lightwell aims to integrate them into a cohesive platform that enables organizations to verify every stage of the software delivery process.

The expanded commercial offerings provide capabilities for artifact signing, provenance generation, policy validation, and lifecycle management, helping organizations implement supply chain security without assembling multiple disconnected open-source projects themselves. This is particularly relevant as AI-assisted development increases both the speed and volume of software changes entering enterprise delivery pipelines.

This has shifted attention toward cryptographic provenance and continuous verification. Rather than relying solely on code reviews or vulnerability scanning, organizations are increasingly seeking evidence that software was built in approved environments, signed using trusted identities, generated from verified source code, and has remained unaltered throughout its lifecycle. In this model, trust becomes an attribute that accompanies software from development through deployment rather than a final security check performed immediately before release.

Rather than introducing entirely new security concepts, Lightwell packages many of these emerging standards into a commercially supported platform that organizations can adopt more easily within enterprise software delivery environments. The emphasis is less on replacing existing security controls than on operationalizing them consistently across increasingly complex development ecosystems.

The announcement also reflects an important evolution in software engineering. Traditionally, software supply chain security focused on preventing malicious code from entering build pipelines. Increasingly, however, organizations need to establish trust not only in source code but also in AI-generated artifacts, automated workflows, infrastructure changes, and autonomous software delivery processes.

As AI agents become capable of generating code, modifying infrastructure, resolving incidents, and contributing directly to software delivery, organizations need mechanisms to verify who, or what, performed each action, under which identity, and according to which policies. This aligns with broader industry efforts around verifiable execution, cryptographic attestations, workload identity, and policy-as-code, all of which seek to make increasingly autonomous software systems transparent and accountable.

IBM and Red Hat are part of a much broader movement toward trusted software supply chains. GitHub has continued expanding provenance capabilities through CodeQL, artifact attestations, and secret scanning, while Google has driven adoption of SLSA and Sigstore across its software ecosystem. Microsoft has integrated software signing and provenance into Azure DevOps and GitHub Advanced Security, and the Cloud Native Computing Foundation (CNCF) recently partnered with Kusari to strengthen supply chain security across cloud-native projects. Meanwhile, initiatives such as the Linux Foundation's Akrites project are exploring how similar cryptographic trust models can protect open-source software from emerging AI-enabled threats.

Although these initiatives differ in implementation, they share a common objective: ensuring that software can be trusted not simply because it functions correctly, but because its entire lifecycle, from source code to deployment, is verifiable, transparent, and resistant to tampering. Lightwell extends this philosophy into the AI era by recognising that trust must increasingly encompass not only human developers but also AI systems participating in software creation.

IBM's expansion of Lightwell suggests that the future of software security will depend less on individual security tools and more on comprehensive trust architectures that span the entire software lifecycle. As AI accelerates development and automation becomes increasingly autonomous, organizations will need stronger guarantees that every artifact, dependency, and deployment can be traced back to a verified source and validated against organizational policy.

About the Author

Craig Risi

Show moreShow less

Rate this Article

Adoption
Style

This content is in the DevOps topic

Related Topics:

Related Content

The InfoQ Newsletter

A round-up of last week’s content on InfoQ sent out every Tuesday. Join a community of over 250,000 senior developers. View an example

We protect your privacy.

BT

AltStyle によって変換されたページ (->オリジナル) /