IBM and Red Hat report hundreds of open source fixes with Lightwell Clearinghouse scheme
IBM and Red Hat's Lightwell Clearinghouse is now GA — a priority-remediation scheme for open source vulnerabilities affecting enterprise stacks.

Why it matters
Lightwell Clearinghouse offers firms a mechanism to request expedited security reviews and fixes for open source dependencies. For enterprises managing large dependency trees, this addresses a real bottleneck: waiting for community maintainers to patch critical vulnerabilities. The catch: no pricing, SLA, or coverage criteria disclosed; unclear whether this scales beyond 'hundreds of fixes' or prioritizes enterprise customers.
The key facts
11 to knowLightwell Clearinghouse now generally available (GA)
Allows firms to request priority review and remediations for open source software
IBM and Red Hat backing
Hundreds of open source fixes reported
No SLA, pricing model, or coverage guarantee disclosed
No independent verification of remediation speed or breadth
Lightwell Clearinghouse now generally available (GA status confirmed)
Hundreds of open-source security fixes reported through the program
Firms can request priority review and remediation for open-source software
IBM and Red Hat joint initiative
Focus on supply-chain security and open-source maintenance
Go to the source
ITProitpro.com
Publisher excerpt: Lightwell Clearinghouse is now generally available, allowing firms to request priority review and remediations for open source software