Broadcom launches TrueSource open source software security portfolio
Broadcom Inc. (NASDAQ: AVGO) announced TrueSource, a portfolio of commercially supported, verifiably built open source software for enterprise customers, at VMware Explore 2026 in Las Vegas.
The portfolio includes three offerings: Spring Enterprise, which provides secure releases of the Spring ecosystem; TrueSource Trusted Artifacts, which offers clean-room builds of Java, Python, and Node.js libraries along with hardened container images from the Bitnami Secure Images catalog; and TrueSource Data Services, which covers PostgreSQL, RabbitMQ, MySQL, and Valkey data engines.
Each offering is built on shared principles, including human-verified patches, upstream remediation with open source maintainers, patch automation tooling, and early access to vulnerability remediation for licensed customers. Critical infrastructure organizations can access a dedicated program for patch insights and mitigation guidance.
Broadcom cited research from 1Password's Off-by-1 Labs, which found that only 26% of 6,000 AI-generated patches fixed vulnerabilities without breaking applications, as context for its human-verification approach. The company said its Spring engineering team has spent more than 12 billion tokens against frontier models over the past five months, with engineers verifying each resulting fix.
"The world's most essential businesses run on open source software, and they trust us to keep that foundation secure," said Ram Velaga, president of Broadcom's Infrastructure Software Group. "With TrueSource, we are making a long-term commitment to our customers: our fixes are built and verified by our engineers, working alongside the maintainers who know the code best."
TrueSource Trusted Artifacts provides SLSA Build Level 3 builds and covers more than 5,000 verified Java libraries. Spring Enterprise patches all supported release lines before a CVE is published, according to the company.
Katie Norton, research director for IDC's Cloud Security research practice, said Broadcom's approach of pairing upstream remediation with human-verified engineering is "one response" to risks posed by AI-generated patching outside maintained upstream projects.
All three offerings are available with tiered site licensing options.
