IBM and Red Hat Expand Lightwell to Build Trusted Software Supply Chains for AI Era
IBM and Red Hat announced the expansion of Lightwell, a commercial product designed to help organizations create trusted, verifiable software supply chains for AI-assisted development. The product integrates signing, provenance, artifact verification, and policy enforcement into a unified platform, addressing the challenge of proving software integrity as AI accelerates development.
IBM and Red Hat have announced an expansion of Lightwell, introducing a new commercial offering aimed at helping organizations build trusted, verifiable software supply chains for the era of AI-assisted software development. The product builds on the open-source Lightwell project and is designed to simplify software signing, provenance tracking, artifact verification, and policy enforcement, ensuring that software—whether generated by humans or AI—is trustworthy throughout the delivery lifecycle. Lightwell consolidates multiple emerging security standards, including Sigstore, in-toto, SLSA, and SBOM, into a cohesive platform that integrates signing, provenance tracking, and policy enforcement rather than treating them as separate activities. The expanded commercial product provides capabilities such as artifact signing, provenance generation, policy verification, and lifecycle management, enabling organizations to implement supply chain security without assembling fragmented open-source components. This shift reflects a broader trend in software engineering where trust becomes an attribute that accompanies software from development to deployment, rather than a final security check before release. As AI agents increasingly generate code, modify infrastructure, and participate in software delivery, organizations need mechanisms to verify which identity performed each action and under what policies, aligning with industry efforts around verifiable execution, cryptographic attestations, workload identity, and policy-as-code. IBM and Red Hat are part of a wider movement including GitHub with CodeQL and artifact attestations, Google's adoption of SLSA and Sigstore, Microsoft's integration of signing into Azure DevOps and GitHub Advanced Security, and CNCF's collaboration with Kusari. The expansion of Lightwell signifies a future where software security relies less on isolated tools and more on comprehensive trust architectures spanning the entire software lifecycle.
Source: InfoQ 中国 —
original
