Forgot your password?
typodupeerror
Security Java Open Source Python

Broadcom Pledges to Lock Down Open Source Python, Java Libraries (theregister.com) 32

Broadcom is launching "TrueSource," an effort to curate and secure open-source components used with its Tanzu platform, including Spring, RabbitMQ, and libraries across Java, Python, and Node.js. "The idea is to provide a set of solutions focused on providing clean and secure artefacts," Purnima Padmanabhan, vice president of Broadcom's Tanzu Division, told The Register. "We choose and build every Spring library, databases, other Java components," she said. The Register reports: Padmanabhan said that promise means VMware will also provide "TrueSource trusted artifacts" for code that is not part of Spring, including the wider Java ecosystem, Python, and Node.js. "Broadcom's curation process ensures that the libraries conform to a reference architecture and are supportable by the maintainers of record," according to a company statement. "Thousands of engineers across Broadcom's software divisions scan, fix, contribute to, and consume them every day."

A VMware spokesperson told The Register the Broadcom business unit "will work with and support maintainers on open source software and we will provide fixes to open source upstream for any active projects." "With Spring and RabbitMQ, we are the maintainers. For other open source software, we will work with the maintainers. We believe that the community maintainers must remain the source of truth," the spokesperson said.

This is just the sort of contribution that the open-source community wants vendors to do to reflect the value they extract from software they did not create alone. It's also the sort of thing vendors sometimes conclude they need to do to keep products based on FOSS viable.

Broadcom Pledges to Lock Down Open Source Python, Java Libraries

Comments Filter:
  • Here We Go Again (Score:5, Insightful)

    by SlashbotAgent ( 6477336 ) on Monday August 31, 2026 @05:06PM (#66316398)

    Another walled garden. That's a no thanks from me.

    From Broadcom. That's a fuck off and die from me.

    If you use Broadcom software and have a negative experience, you can only blame yourself.

    • by gweihir ( 88907 )

      If you use Broadcom software and have a negative experience, you can only blame yourself.

      Let me fix that:
      "If you use Broadcom software you will have a exceptionally negative experience and you can only blame yourself."

      It is like Oracle or Microsoft customers asking for more punishment ...

  • and say this sounds like a very good thing, on the surface

    • by Revek ( 133289 ) on Monday August 31, 2026 @05:16PM (#66316422)
      Just another move to remove choice.
      • by PPH ( 736903 )

        You can still download from the traditional sources.

        • by Anonymous Coward

          Not so fast! Wow! With its acquisition of VMWare, Broadcom *owns* the spring framework now...
          https://en.wikipedia.org/wiki/... [wikipedia.org]

          I guess I'll just stick to Apache struts instead for my web apps then. The Apache foundation should be the last one to pull such shenanigans.

          And I'll just keep using Apache ActiveMQ and forget forever about ever using RabbitMQ...

    • > and say this sounds like a very good thing, on the surface

      Indeed. It's a curated set of open source libraries that you can use if you want to. They're curated, so they won't contain the latest supply chain attacks, and will have security fixes in them where needed. Use what you want, whenever you like and know that you're going to be 'safe' to do so. Pretty good, right?

      That's how it's "spun", but the reality is slightly different. Likely it'll be old versions with fixes back ported, which will mean you

  • by MpVpRb ( 1423381 ) on Monday August 31, 2026 @05:16PM (#66316420)

    ...the competition for worst company in tech
    In this corner, Apple
    In this corner, Broadcom

  • Buy A Mirror. (Score:5, Interesting)

    by geekmux ( 1040042 ) on Monday August 31, 2026 @05:32PM (#66316456)

    Broadcom is launching "TrueSource,"..

    The VMWare murderer needs to invest in a fucking mirror and read the damn room.

    As if they can sell their True intent to anyone but an investor armed with fucking fangs these days.

    • Re:Buy A Mirror. (Score:4, Insightful)

      by dynamo ( 6127 ) on Monday August 31, 2026 @05:57PM (#66316490) Journal

      Yeah, the company that killed VMWare is in no position to be deciding which open source software is acceptable and which is not. They'll probably (in time) require a payment for a positive review - and pretend to cover their asses by requiring payment for a review at all, but out of the theoretical kindness of their hearts, they'll do free reviews that all just happen to come out negative. Anyone who walks into this trap after knowing what they did to VMWare gets what they deserve.

    • by gweihir ( 88907 )

      One correction: These fucks do not need a mirror. They KNOW they are evil assholes. Who needs to realize what is going on is their remaining customers.

  • by zeiche ( 81782 ) on Monday August 31, 2026 @06:50PM (#66316600)
    they are trying to suggest that locking down FOSS is exactly what the open source community has been demanding. just like how companies delude themselves into thinking that customers are desperate for targeted advertising and subscriptions.

    enshitification continues unabated.
  • by HotNeedleOfInquiry ( 598897 ) on Monday August 31, 2026 @07:29PM (#66316650)

    Are two phrases I generally don't use in the same sentence.

    • That wording seems intentionally designed by some marketing shitbag to cause chatter among us rubes, increase engagement, and get the word out. It does not, however, seem to be designed to paint the company in a positive light while creating that chatter. It's almost like they've decided their brand now is, "Fuck you, give us money, and we'll see what we can fuck you with next." Let's see how that plays out long term for them.

  • by Meneth ( 872868 ) on Monday August 31, 2026 @08:21PM (#66316704)
    Curation of libraries, separate from their developers, has long been missing from PyPI, npm, Cargo and other such platforms, to mitigate supply-chain attacks. I welcome the idea, but it needs a better steward than Broadcom.
    • Jfrog's Artifactory + Xray is such a solution. It is not perfect as it doesn't execute the complex steps an antivirus solution usually has like running code in a sandbox. But it has approvals, audit logs, CVE scan for most popular package formats. And it can be deployed fully isolated on-prem. It is not cheap, but for Broadcom customers that shouldn't be an issue :)
  • by NotEmmanuelGoldstein ( 6423622 ) on Monday August 31, 2026 @08:42PM (#66316724)
    Broadcom realizes the free software they're getting is valuable and are taking steps to protect it, especially from AI-generated malware. Given their need to monetize everything, I expect them to invoice the software contributors for the right to work for nothing.
  • by Anonymous Coward

    A couple years ago, Broadcom started to withhold security fixes for older versions of Spring unless you agreed to pay some truly exorbitant fees (millions in some cases) for access. They could be the poster children for enshittification, but they'd charge for the poster.

    I wouldn't trust anything they've touched.

  • This is based on SLSA (Supply-chain Levels for Software Artifacts), brought to you by the same fuckers making Trusted Computing and the TMP (Trusted Platform Module). It's part of the same shitstack to prohibit you from altering your software and to lock you out of your own files, and to send spy reports out over the internet so you can be cut off if you "fail" the Trusted Computing check.

    The software can use a TPM's (Trusted Platform Module) Sealing function to encrypt your data such that it's impossible t

    • by gweihir ( 88907 )

      Indeed. It is an obvious trap. Do not fall for it.

      I do hope that Broadcom has achieved trust levels enough after all the crap they pulled so far that this will not fly. But who knows.

      • Indeed. It is an obvious trap. Do not fall for it.

        I do hope that Broadcom has achieved trust levels enough after all the crap they pulled so far that this will not fly. But who knows.

        Somewhere, there's a drooling management team convinced that Broadcom is still a name to trust, foisting this bullshit onto an IT team that will be punished when the rug inevitably gets pulled.

    • by tepples ( 727027 )

      In the long term, the goal is for ISPs to use NAC/TNC to interrogate your computer for Trusted Computing compliance, and deny you any internet access whatsoever if your machine isn't compliant.

      You said home ISPs sought to deploy Trusted Network Connect about 20 years ago. It hasn't happened. What's holding it up? The rise of mobile devices, smart TVs, and other devices incompatible with the remediation means available in quarantine?

  • Broadcom has "TrueSource".
    Red Hat has Lightwell.
    Chainguard has their SBOMs.

    All of them trying to cover the AI slop flood, for those who pay, in a manner dictated by their AI solutions, thrown at upstream communities to take "as-is".
    And not once do any of them actually try to solve the problem, by throwing money/support/staff to assist reviewers. Just generate more work against those already taken for granted. Finding a way to make a buck in the slop-flood.

  • Or rather lock people in and then charge them an arm and a leg. Obviously, privacy and security will not be delivered, that is just a convenient lie to bait the trap.

    Anybody that falls for this obvious scheme needs to have their head examined.

  • I mean we already have sources of trustable code, they are called distributions and provide working, yet a bit stale, versions of popular software packages. Even the fact that they are not "bleeding edge" already makes them more secure since they had a bit of a "shake down period". It's not like a developer commit will make it straight into deployment.

This place just isn't big enough for all of us. We've got to find a way off this planet.

Working...