On October 6, IBM announced that Lightwell Clearinghouse was generally available to enterprise customers seeking priority review and remediation of specific open-source dependencies. IBM and Red Hat also reported that Lightwell had remediated more than 400 previously unknown vulnerabilities in widely used Java libraries.

IBM announced general availability for Lightwell Clearinghouse

The service gives enterprise customers a channel to submit specific open-source dependencies for priority review and remediation. Red Hat describes Lightwell as an annual subscription with two paths: Lightwell Network and Lightwell Clearinghouse.

What IBM and Red Hat reported about the Java vulnerabilities

The companies’ reported total covers more than 400 previously unknown vulnerabilities in widely used Java libraries. IBM also describes Lightwell’s work as covering production-grade software, including versions already in use.

The practical point is the focus on existing software: organizations can seek fixes for the versions they run, rather than treating an upgrade to a different dependency version as the only route to remediation.

How Lightwell describes fixes for production software

An earlier Lightwell overview describes AI-assisted triage alongside human verification

IBM says Lightwell develops version-specific fixes and backports them to software versions already in production. A backport applies a fix to an older software version, so teams can address a vulnerability without moving their application to a newer dependency version.

The companies describe delivery through secured repositories that fit into existing IT processes. IBM says customers can continue using their scanners, repositories, development pipelines and testing processes. Applicable fixes are also contributed to upstream open-source projects under responsible-disclosure protocols.

A June 24, 2026, Lightwell overview describes AI-assisted triage and code correction alongside human verification. It also presents keeping existing dependencies as part of the remediation approach.

Lightwell Network and Clearinghouse serve different paths

Red Hat describes Lightwell Network as consolidated self-service access to signed libraries, remediations and patched artifacts for eligible vulnerabilities. Clearinghouse adds customer-specific vulnerability and package requests within an approved scope, along with verification, disclosure coordination and security technical account management services. The two paths are offered as annual subscriptions.