Broadcom launches TrueSource for secure open source software
- Broadcom launches TrueSource portfolio for secure open source software
- Offerings cover Spring, Java, Python, Node.js, and data engines like PostgreSQL
- Strategy prioritizes human-verified patches over fully automated AI fixes
- Testing showed only 26% of AI-generated patches worked without breaking apps
- Service uses frontier models for scanning but engineers verify every fix

*this image is generated using AI for illustrative purposes only.
Broadcom Inc. (NASDAQ: AVGO) launched TrueSource, a portfolio of commercially supported open source software designed to secure enterprise supply chains. The announcement came at VMware Explore 2026 in Las Vegas on August 31, 2026.
The offering addresses rising security risks in open source ecosystems by providing verifiably built libraries and artifacts. Broadcom positions the suite as an alternative to fully automated patching, which it argues carries operational risks.
Product Portfolio
TrueSource comprises three main components targeting different layers of the technology stack:
- Spring Enterprise: Focuses on the Spring ecosystem, providing curated releases and human-verified patches.
- TrueSource Trusted Artifacts: Covers the broader Java ecosystem, Python, Node.js, and includes hardened container images via the Bitnami Secure Images catalog.
- TrueSource Data Services: Extends security coverage to data engines including PostgreSQL, RabbitMQ, MySQL, and Valkey.
Security Methodology
Broadcom emphasizes human-verified engineering over automated AI-generated fixes. The company cites testing by 1Password’s Off-by-1 Labs, which found that only 26 percent of 6,000 AI-generated patches fixed vulnerabilities without breaking applications.
Spring Enterprise leverages over 20 years of maintenance experience. Engineers scan the Spring dependency tree using frontier model analysis but verify every patch manually. In the past five months, this process consumed more than 12 billion tokens against frontier models.
The service provides simultaneous patches across all supported release lines before CVE publication. Coverage extends beyond Spring itself to managed dependencies, including Apache Tomcat and Kotlin, covering more than 5,000 verified Java libraries.
Ecosystem Expansion
TrueSource Trusted Artifacts offers SLSA Build Level 3 builds for Java, Python, and Node.js libraries. These are curated against a reference architecture to ensure supportability by maintainers of record.
TrueSource Data Services applies similar rigor to data engines. The offering includes deployment automation and visibility into security posture for PostgreSQL, RabbitMQ, MySQL, and Valkey.
What the Numbers Show
The disparity between AI efficiency and reliability is stark in the cited data. While AI scanning scaled to process over 12 billion tokens in five months, the external test showed a 74 percent failure rate for unverified AI patches. This divergence underscores Broadcom’s strategy of using AI for detection while retaining human engineers for remediation to prevent application breakage.
Availability
Spring Enterprise, TrueSource Trusted Artifacts, and TrueSource Data Services are available with tiered site licensing options. The launch follows a June commitment by Broadcom to enhance Spring supply chain security.
How might Broadcom's human-verified patching model impact the total cost of ownership for enterprises compared to fully automated AI-driven security solutions?
Will the emphasis on SLSA Build Level 3 compliance in TrueSource Trusted Artifacts drive broader industry adoption of supply chain attestation standards?
How could competitors in the open-source security space, such as GitHub or Snyk, respond to Broadcom's hybrid AI-human verification strategy?
































