IBM and Red Hat Bolster Lightwell for Trustworthy AI-Powered Software Supply Chains
IBM and Red Hat have expanded Lightwell, introducing new commercial offerings that aim to secure AI-assisted software supply chains. This expansion addresses the growing challenge of ensuring the integrity of both human- and AI-generated software throughout the development and delivery lifecycle.
The new offerings simplify software signing, provenance, and artifact verification by integrating Sigstore, in-toto, SLSA, and SBOM standards. By treating these security activities as interconnected components rather than separate entities, Lightwell enables verification at every stage of the software delivery process.
This shift towards cryptographic provenance and continuous verification underscores a growing need for organisations to demonstrate evidence that their software was built in approved environments, signed with trusted identities, generated from verified source code, and remained unaltered. As AI becomes capable of generating code, modifying infrastructure, and contributing to delivery, organisations require mechanisms to verify who or what performed each action.