Broadcom recently announced the TrueSource project during VMware Explore 2026. This initiative offers enterprise customers verified and traceable open-source software builds. These builds also include full commercial support. The project does not aim to commandeer these open-source tools. Instead, it delivers secure, patched, and rebuilt packages. These packages rely entirely on the original upstream source code. Broadcom will not pay the upstream software maintainers. The company will, however, submit discovered security fixes back upstream.
Combating Supply Chain Attacks
Broadcom developed this program to counter frequent supply chain attacks. Modern enterprises desperately require stable and reliable software sources. Security and stability remain paramount for corporate clients. Therefore, Broadcom hopes the TrueSource project will attract paying enterprise customers.
AI-Driven Security Scanning
The mechanics of the TrueSource project remain straightforward. Broadcom will systematically collect over 5,000 common dependency libraries. Advanced AI models will continuously scan these libraries for vulnerabilities. These AI models will also implement fixes for any discovered flaws. Human experts will then manually verify the generated patches. They will merge the confirmed fixes into the software packages. Finally, the system delivers these fully verified packages to enterprises.
Paying customers avoid verifying massive dependency trees manually. They no longer need to check container images or database components. Instead, they directly receive versions verified by Broadcom. The company has not yet announced specific pricing for TrueSource.
Collaborating With Upstream Maintainers
Broadcom promises to collaborate actively with open-source project maintainers. The company will submit vulnerability fixes to active upstream projects. Broadcom refuses to maintain closed, private branches over the long term. However, some projects may currently lack active maintenance. Broadcom might not submit fixes to these inactive upstream repositories. Submitting patches to abandoned projects proves largely useless. In these cases, enterprise customers rely on Broadcom’s verified packages. They will continue receiving essential security maintenance services through this subscription.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!