Broadcom launches TrueSource for secure open source
Mon, 31st Aug 2026 (Yesterday)
Broadcom has launched TrueSource, a portfolio of commercially supported open source software for businesses. It combines application frameworks, software libraries and data services.
The range includes Spring Enterprise, TrueSource Trusted Artifacts and TrueSource Data Services. Broadcom said it is designed to give customers access to software its engineers have built and verified across the Java, Python and Node.js ecosystems, alongside container images and supported distributions for PostgreSQL, RabbitMQ, MySQL and Valkey.
The launch extends Broadcom's recent focus on software supply chain security around Spring, the widely used Java framework. It also places the company in a growing debate over how far artificial intelligence can be trusted to identify and fix vulnerabilities in open source software without direct human review.
Broadcom said every library and software artifact in the TrueSource range is selected against a reference architecture, then built and verified by its engineers. Fixes are contributed upstream to maintainers rather than handled outside the main open source projects.
Its tooling also scans customer repositories, assesses the impact of software releases before adoption and opens pull requests with what Broadcom described as the lowest-risk route to remediation. Dashboards are intended to show security teams what has been fixed and what remains unresolved.
Spring focus
Spring Enterprise remains the centrepiece of Broadcom's push in this area. The product offers curated Spring releases from the team that maintains the framework, with support extending beyond Spring itself to managed dependencies including Apache Tomcat and Kotlin, as well as more than 5,000 verified Java libraries tied to supported Spring Boot release lines.
Broadcom said customers would receive patches across every supported release line before a CVE is published. Security fixes can also be provided separately from full point releases, allowing teams to apply remediation without taking broader code changes at the same time.
Broadcom linked the launch to rising pressure on defenders as AI tools speed up the discovery and exploitation of software flaws. It cited testing by 1Password's Off-by-1 Labs that found only 26% of 6,000 AI-generated patches fixed vulnerabilities without breaking applications.
“The world's most essential businesses run on open source software, and they trust us to keep that foundation secure,” said Ram Velaga, President, Infrastructure Software Group, Broadcom. “As AI accelerates both innovation and exploitation, that trust cannot rest on unverified, machine-generated patches. It has to rest on accountable engineering. With TrueSource, we are making a long-term commitment to our customers: our fixes are built and verified by our engineers, working alongside the maintainers who know the code best.”
Broader coverage
TrueSource Trusted Artifacts broadens the scope beyond Spring. Broadcom said the service provides clean-room builds at SLSA Build Level 3 for software libraries across Java, Python and Node.js, and includes the Bitnami Secure Images catalogue for container images covering hundreds of open source packages.
According to Broadcom, the libraries are curated to conform to a reference architecture and remain supportable by the maintainers of record. Engineers across its software divisions already scan, fix, contribute to and use these components in products sold to customers, the company said.
TrueSource Data Services applies the same approach to databases and messaging systems. The offering covers PostgreSQL, RabbitMQ, MySQL and Valkey, and includes validated distributions, critical extensions, operators, Helm charts, deployment automation and visibility into security and operational posture.
Broadcom argued that patching at the data layer requires operational judgement because a flawed fix can put underlying data at risk. The claim is part of its broader effort to present human-reviewed remediation as more dependable than automated patch generation alone.
“Open source security is a human discipline,” said Purnima Padmanabhan, Vice President and General Manager, Tanzu Division, Broadcom. “AI is a phenomenal accelerant for the engineers who maintain this software, not a replacement for them. Maintainers understand the intent behind the code, and that is what separates a real fix from one that just looks like it. TrueSource puts that human expertise at the center of the open source supply chain, at commercial scale.”
Industry analysts are also watching the issue. “AI-generated patching, when applied outside a maintained upstream project, risks producing forks that lack maintainer oversight and long-term accountability,” said Katie Norton, Research Director for IDC's Cloud Security research practice. “Broadcom's approach with Spring, pairing upstream remediation with human-verified engineering, is one response to this trend, intended to support the integrity and sustainability of the open source supply chain.”
Broadcom said its Spring engineering team has scaled AI-based scanning and validation across the dependency ecosystem while keeping authorship, review and verification with engineers. That work was carried out in response to a rise of more than 1,700% in monthly security advisories reported by the Spring community and led to the largest set of security patches in the framework's 23-year history.
The three TrueSource offerings are available under tiered site licensing options.