Broadcom Expands Open Source Security with TrueSource, Targeting Java, Python, Node.js Ecosystems

  • Broadcom launched TrueSource, a portfolio of commercially supported, verifiably built open source software for enterprises, covering Java, Python, and Node.js ecosystems.
  • TrueSource includes Spring Enterprise for Spring ecosystem security, TrueSource Trusted Artifacts for secure builds, and TrueSource Data Services for PostgreSQL, RabbitMQ, MySQL, and Valkey data engines.
  • Broadcom engineers have spent over 12 billion tokens in the past five months using frontier models to scan and verify patches.
  • 1Password’s Off-by-1 Labs found that only 26% of AI-generated patches fixed vulnerabilities without breaking applications.
  • TrueSource offerings are available with simple, tiered site licensing options.

Broadcom’s TrueSource launch addresses the critical need for secure, verifiably built open source software as AI accelerates both innovation and exploitation. The company’s focus on human-verified patches contrasts with the industry’s shift towards AI-generated solutions, highlighting the tension between automation and accountability in software security. With the surge in security advisories and the complexity of managing open source dependencies, Broadcom aims to set a new standard for enterprise-grade open source security.

AI Reliance
How Broadcom’s human-verified patching approach will compete against the growing trend of AI-generated patches in the open source ecosystem.
Market Adoption
The pace at which enterprises will adopt TrueSource offerings given the increasing threats to open source software supply chains.
Competitive Response
Whether competitors will respond with similar human-centric approaches to open source security or continue to rely on automated solutions.