SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Broadcom launches TrueSource to bolster open source security

Broadcom launches TrueSource to bolster open source security

Fri, 2nd Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Broadcom has launched TrueSource, a portfolio of commercially supported open source software offerings spanning application frameworks, software libraries and data services.

The launch brings together Spring Enterprise, TrueSource Trusted Artifacts and TrueSource Data Services under one brand. The products target organisations seeking supported open source components built and verified by Broadcom engineers.

The move expands Broadcom's earlier focus on Spring, the Java framework ecosystem widely used in business applications. It also extends the company's security and support model beyond Spring into Java libraries, as well as Python, Node.js and several data engines.

Broader scope

Spring Enterprise remains the centrepiece. It provides curated Spring releases from the team that develops and maintains the framework, alongside security fixes across supported release lines.

The service also covers dependencies linked to Spring deployments, including Apache Tomcat and Kotlin, and extends across more than 5,000 Java libraries tied to supported Spring Boot release lines. Customers can receive CVE-only patches separately from full point releases, allowing security changes to be applied without broader software upgrades.

TrueSource Trusted Artifacts extends that model to other software ecosystems. The offering provides clean-room builds at SLSA Build Level 3 for libraries in Java, Python and Node.js, alongside a catalogue of hardened container images through Bitnami Secure Images.

TrueSource Data Services applies the same approach to software used in the data layer. The service covers PostgreSQL, RabbitMQ, MySQL and Valkey, and includes support for related extensions, Operators and Helm Charts, as well as deployment automation and visibility into security and operations.

Security pressure

Broadcom positioned the launch as a response to the increasing speed of software vulnerability exploitation and concerns about relying on automated patching alone. It cited research from 1Password's Off-by-1 Labs showing that only 26 per cent of 6,000 AI-generated patches fixed vulnerabilities without breaking applications.

That finding has become part of a wider debate in software development over AI's role in vulnerability management. Suppliers have pushed more automation into patching workflows, but maintainers and security teams have raised concerns about software stability, accountability and the creation of unsupported code forks.

Broadcom said its model uses AI for scanning and validation, while engineers remain responsible for authoring, reviewing and verifying fixes. The company added that its Spring engineering team had used more than 12 billion tokens against frontier models in recent months as part of that process.

Ram Velaga, President, Infrastructure Software Group at Broadcom, set out the company's view on balancing automation with human oversight.

"The world's most essential businesses run on open source software, and they trust us to keep that foundation secure," said Velaga. "As AI accelerates both innovation and exploitation, that trust cannot rest on unverified, machine-generated patches. It has to rest on accountable engineering. With TrueSource, we are making a long-term commitment to our customers: our fixes are built and verified by our engineers, working alongside the maintainers who know the code best."

Maintainer role

A key part of the strategy is Broadcom's emphasis on upstream involvement rather than creating parallel fixes outside community projects. The company contributes fixes upstream and provides engineering time and funding to maintainers across the industry.

Customers using the products can also access automation that scans repositories, assesses the likely impact of releases before adoption and opens pull requests with what Broadcom described as the lowest-risk remediation path. Dashboards are designed to show what has been fixed and what remains unresolved.

Licenced users also have the option to bring forward vulnerabilities that have not yet been made public for early remediation access. Broadcom added that critical infrastructure organisations can obtain dedicated access to patch insights and mitigation advice.

Purnima Padmanabhan, Vice President and General Manager, Tanzu Division at Broadcom, said the company sees AI as an assistive tool rather than a substitute for software maintainers.

"Open source security is a human discipline," said Padmanabhan. "AI is a phenomenal accelerant for the engineers who maintain this software, not a replacement for them. Maintainers understand the intent behind the code, and that is what separates a real fix from one that just looks like it. TrueSource puts that human expertise at the center of the open source supply chain, at commercial scale."

Outside analysts broadly share concerns about patch quality and long-term stewardship when fixes are generated away from upstream projects. IDC's cloud security research practice said the issue goes beyond whether a patch works in the short term and includes who remains responsible for maintaining it.

"AI-generated patching, when applied outside a maintained upstream project, risks producing forks that lack maintainer oversight and long-term accountability," said Norton. "Broadcom's approach with Spring, pairing upstream remediation with human-verified engineering, is one response to this trend, intended to support the integrity and sustainability of the open source supply chain."