Fix open source vulnerabilities faster with Lightwell
Find and fix vulnerabilities early: Stop fighting today’s cyberattacks with yesterday’s AppSec tools
Open source software is essential to modern application development, but vulnerable dependencies can create difficult choices for security, engineering, and platform teams. When a straightforward upgrade is not possible, organizations may be forced to maintain private patches, delay remediation, or devote significant engineering effort to backporting and validating fixes. In this episode, we will explain what Lightwell is, the problem it addresses, and how it fits into the software development lifecycle. Attendees will learn how Lightwell helps organizations access remediated open source packages for eligible dependencies while maintaining the versions their applications rely on. We will also walk through the Lightwell operating model, including how packages are identified, remediated, validated, signed, and delivered for use within existing customer environments. The session will clarify what Lightwell provides, what responsibilities remain with the customer, and how security, platform engineering, and application teams can work together to evaluate whether Lightwell is appropriate for their environment. This episode is for security, application development, platform engineering, and infrastructure leaders who want a clearer understanding of Lightwell and its role in reducing the operational burden associated with vulnerable open source dependencies. Key takeaways: Why vulnerable open source dependencies can be difficult to remediate without disrupting production applications What Lightwell is and the use cases it is designed to address How the Lightwell package remediation, validation, signing, and delivery process works How Lightwell fits into existing security, development, and release workflows What customers should consider when evaluating package eligibility, coverage, and organizational fit
Vincent Tsugranes is Red Hat’s Chief Architect for the Healthcare and Aviation industries, helping Red Hat build tools that solve interesting customer problems the Open Source way. He has 25 years of experience leading Architecture, Software Engineering, Operations, and Emerging Technology. He holds a Masters in Management from Harvard, runs a small farm, and is a big fan of Agricultural Technology.