Skip to main content

Broadcom Launches Trusted Artifact Service for Spring Framework

Broadcom today at the VMware World Explore conference a set of hardened artifacts for the open source Spring framework, including the 5,000 dependencies that are needed to run it.

TrueSource Trusted Artifacts by Broadcom provides access to artifacts built in a clean room, including instances of Apache Tomcat, Kotlin, PostgreSQL, RabbitMQ, MySQL, and Valkey databases and middleware. It also extends to the Bitnami Secure Images catalog, adding hardened, verifiably built container images for hundreds of commonly used open source packages.

Based on the enterprise edition of the Spring framework that Broadcom supports, TrueSource Trusted Artifacts by Broadcom includes curated artifacts written in Java, Python and Node.js. Every library and artifact is selected against a reference architecture, then built and verified by human Broadcom engineers. That aspect of the service is critical because patches generated by AI coding that have not been validated by software engineers are much more likely to break an application running in a production environment.

Broadcom, via this service, will also scan customer repositories, assess the potential blast radius of each release, and then open pull requests based on the lowest-risk remediation path determined. There is also a set of dashboards through which DevSecOps teams can track what has been fixed and what tasks remain to be completed.

DevSecOps teams will also have the option to bring not-yet-public vulnerabilities they discover for early access remediation. In addition, there is a special program for critical infrastructure organizations that provides them with dedicated access to patch insights and mitigation advice.

Finally, Broadcom is committing to contributing the fixes it creates back to the maintainers of the open source software that it has remediated.

Purnima Padmanabhan, general manager for the Tanzu Division of Broadcom, said TrueSource Trusted Artifacts by Broadcom brings a lot of our open source capabilities together under one umbrella in a way that remains true to open source. In fact, Broadcom claims that over the past five months, engineers have already spent more than 12 billion tokens against frontier models to secure open source projects to ensure that every supported release line is patched before a Spring-related vulnerability is ever published.

Those efforts are crucial because earlier this year Broadcom revealed there has been a more than 1,700% surge in monthly security advisories reported by the Spring community, resulting in the largest set of security patches in Spring’s 23-year history being created and delivered.

Mitch Ashley, vice president and practice lead for software lifecycle engineering at The Futurum Group, said a curated pipeline inside the customer’s own build and deploy path addresses a key software supply chain requirement. Teams pull libraries, images, and data engines already built, signed, and pinned to the versions their release lines support, with automation that opens pull requests carrying the lowest-risk fix, he added.

That removes work enterprises absorb today: Triaging advisories, testing patches, and deciding what is safe to ship, noted Ashley.

It’s not clear to what degree exploits created using AI are starting to overwhelm DevSecOps teams, but the one thing that is clear is nearly all of them will require additional help to keep pace. After all, it’s not so much a question of whether there will now be more incidents so much as how much they can first be prevented and, just as importantly, rapidly contained.



from DevOps.com https://ift.tt/5PRxZfn

Comments

Popular posts from this blog

Mystery Fuels Unease in Maine Woods: Who Bought Burnt Jacket Mountain?

Mystery Fuels Unease in Maine Woods: Who Bought Burnt Jacket Mountain? By Jenna Russell, Heather Knight and Sophie Park from NYT U.S. https://ift.tt/a6Ye2Gp Land Use Policies, High Net Worth Individuals, Forests and Forestry, Logging Industry, Real Estate and Housing (Residential), Facebook Inc, Thomas Associates, Zuckerberg, Mark E, Chan, Priscilla, Appalachian Trail, Bangor (Me), Maine, Palo Alto (Calif), Mount Katahdin (Me), Millinocket (Me)

LocalStack Acquires WonderTwin AI to Gain SaaS App Emulation Platform

LocalStack this week revealed it has acquired WonderTwin AI , a provider of an emulator of software-as-a-service (SaaS) applications that is used to build custom applications for those platforms. Colin Neagle, vice president of marketing for LocalStack, said the emulators WonderTwin AI has developed will be integrated into the company’s namesake emulation platform that application development teams currently rely on to emulate cloud services provided by Amazon Web Services (AWS). LocalStack and WonderTwin AI make it possible for application developers working on a local machine to build applications that are designed to be deployed on some type of external cloud platform using a local sandbox to test and validate integrations without having to connect to a service or build against a live application programming interface (API). That issue has been especially critical in an era where more code will soon be generated by AI coding agents that may for one reason or another circumvent the...

Rochelle Walensky on the Rocky Road to Normal

Rochelle Walensky on the Rocky Road to Normal By David Wallace-Wells from NYT Opinion https://ift.tt/0A5Wx6r internal-sub-only-nl, Coronavirus (2019-nCoV), Vaccination and Immunization, Rumors and Misinformation, Centers for Disease Control and Prevention, Walensky, Rochelle