AI News Feed
Market watch
Companies

Broadcom Launches TrueSource to Secure Open-Source Libraries for Tanzu Platform

Broadcom has unveiled TrueSource, an initiative to curate and secure open-source components for its Tanzu platform, covering Spring, RabbitMQ, and Java, Python and Node.js libraries, with fixes promised upstream.

In a report by The Register, Purnima Padmanabhan, vice president of Broadcom's Tanzu Division, explained that TrueSource is designed to offer “a set of solutions focused on providing clean and secure artefacts.” She said Broadcom chooses and builds every Spring library, databases, and other Java components, ensuring they meet corporate standards. The Register noted that Padmanabhan's promise also applies to code outside the Spring ecosystem, with VMware providing “TrueSource trusted artifacts” for the wider Java ecosystem, Python, and Node.js.

A company statement further elaborated that Broadcom’s curation process ensures libraries conform to a reference architecture and are supportable by the maintainers of record. The statement highlighted that thousands of engineers across Broadcom’s software divisions scan, fix, contribute to, and consume these libraries every day. This continuous internal engagement is intended to keep the artifacts reliable and secure without relying solely on external audits.

A VMware spokesperson, speaking to The Register, said the Broadcom business unit will work with and support maintainers on open-source software and will provide fixes to open-source upstream for any active projects. The spokesperson clarified that for Spring and RabbitMQ, Broadcom is the maintainer, while for other open-source projects, it will collaborate with existing maintainers. “We believe that the community maintainers must remain the source of truth,” the spokesperson added.

The initiative has been positioned as a positive step for the open-source community, which has long expected vendors to give back to the projects they depend on. As Slashdot reported, this is just the sort of contribution that the open-source community wants vendors to do to reflect the value they extract from software they did not create alone. It also serves as a practical move to keep FOSS-based products viable by ensuring their underlying components remain secure and well-maintained.