Broadcom Launched TrueSource for Open Source Software

The new portfolio offers commercial support, hardened builds, and AI-assisted security for enterprise applications.

Updated on Oct. 2, 2026 in Software

Isometric editorial illustration of a modular server rack stack, representing enterprise software infrastructure support.
Broadcom has introduced TrueSource, a new enterprise software portfolio providing commercial support and AI-assisted security features for open source infrastructure projects. AI Illustration. Upload story photo >

Live Poll

Do you trust automated tools to secure the software your household or business relies on?

Broadcom has launched TrueSource, a new software portfolio designed to provide commercial support and security for open source projects. The service suite integrates Spring Enterprise, hardened container images, and data services to help organizations manage their software infrastructure.

Why it matters

The service aims to combat the rapid pace of software vulnerability exploitation while addressing industry skepticism regarding the reliability of automated, machine-generated security patches.

The platform provides SLSA Build Level 3 artifacts and hardened images via Bitnami, covering languages and tools like Java, Python, Node.js, and PostgreSQL. Spring Enterprise alone supports 5,000 Java libraries.

The players

Broadcom

Broadcom is a global technology company that designs, develops, and supplies a broad range of semiconductor and infrastructure software solutions.

Spring

Spring is an application framework and inversion of control container for the Java platform that simplifies enterprise software development.

The details

Broadcom utilizes AI-driven scanning to identify security issues, while its engineers manually review, author, and verify all software fixes before deployment. Customers can automate repository scanning and streamline the remediation process through generated pull requests.

Timeline

  1. Broadcom officially launched the TrueSource software portfolio on October 2, 2026.

The Tech Race

This move marks a shift in how enterprises approach open source, moving from community-led maintenance toward vendor-backed reliability. It positions Broadcom against other infrastructure providers by prioritizing verified, human-reviewed security over purely automated patching.

Developers and IT teams can expect reduced manual overhead when securing open source dependencies through integrated automation. Organizations can now rely on commercial support to expedite vulnerability patching without compromising application stability.

The takeaway

Enterprises should balance the efficiency of AI-driven security tools with the necessity of human verification to ensure code integrity. Relying on vendor-hardened images can significantly mitigate the risks associated with vulnerable open source components.

Further reading

For more information on the evolving landscape of enterprise code management, visit the Software section.

Source note: This article includes information reported by SecurityBrief Asia.

Live Poll

Do you trust automated tools to secure the software your household or business relies on?