open source security

Codenotary Uses Claude AI to Secure immudb Development

Codenotary Uses Claude AI to Secure immudb Development

Codenotary has been accepted into Anthropic’s Claude for OSS program, deploying AI assistance to accelerate development of immudb, its open source immutable database. The company is using Claude to detect subtle bugs, analyze concurrency issues, and generate regression tests, while maintaining mandatory human review of all code changes. The move positions Codenotary to ship faster at a moment when enterprise demand for software supply chain security infrastructure is near peak.

Codenotary Uses Claude AI to Secure immudb Development Read More »

Eclipse Foundation & OWASP Unite for CRA Open Source Security

Eclipse Foundation & OWASP Unite for CRA Open Source Security

The Eclipse Foundation and OWASP have signed an MOU to strengthen open source security and support EU Cyber Resilience Act compliance. With mandatory reporting obligations taking effect September 11, 2026, the partnership targets SBOM adoption, supply chain security, and maintainer readiness. ECI Research data shows supply chain security is a top-12-month investment priority for nearly half of enterprise respondents.

Eclipse Foundation & OWASP Unite for CRA Open Source Security Read More »

The 2026 Artifact Management Enforcement Gap | ECI Research

The 2026 Artifact Management Enforcement Gap | ECI Research

Cloudsmith’s second annual Artifact Management Report finds that AI-generated code has become near-universal, but governance hasn’t kept pace. Three in four organizations generate SBOM data without using it for real-time security enforcement. ECI Research examines what the EU Cyber Resilience Act deadline means for teams still relying on manual remediation.

The 2026 Artifact Management Enforcement Gap | ECI Research Read More »

Open Secure AI Alliance: NVIDIA's Bet on Open Cybersecurity

Open Secure AI Alliance: NVIDIA’s Bet on Open Cybersecurity

NVIDIA and more than 40 industry partners have formed the Open Secure AI Alliance, arguing that open AI models and harnesses are essential defensive assets for cybersecurity. The alliance is contributing open agent frameworks, supply chain integrity tools, and zero-trust identity infrastructure to a shared defense stack. ECI Research data shows enterprises already operate in blended open/closed security tooling models, making the alliance’s approach practically relevant today.

Open Secure AI Alliance: NVIDIA’s Bet on Open Cybersecurity Read More »

AI Code Security: Why False Negatives Beat Hallucinations

AI Code Security: Why False Negatives Beat Hallucinations

Sonatype CTO Brian Fox argues that AI coding tools have become more dangerous as they’ve gotten smarter—trading visible hallucinations for silent false negatives that leave vulnerable dependencies undetected. The fix requires grounding AI models in real-time dependency intelligence, not just scanning code after it’s written. ECI Research data confirms AI code governance is the top enterprise security investment priority heading into 2026.

AI Code Security: Why False Negatives Beat Hallucinations Read More »

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

The Eclipse Foundation and ORC Working Group have launched the ORC Learning Hub, a free modular training platform helping developers, maintainers, and security teams prepare for the EU’s Cyber Resilience Act. With the first CRA obligations taking effect in September 2026, the initiative addresses a critical gap in role-specific compliance education for open source software supply chains. ECI Research analysts assess what this means for ITDMs and engineering teams navigating the new regulatory landscape.

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance Read More »

IBM's Enterprise AI Push: Google, ServiceNow, Apptio & Red Hat

IBM’s Enterprise AI Push: Google, ServiceNow, Apptio & Red Hat

IBM has launched four interconnected moves spanning a Google Cloud consulting practice, a ServiceNow modernization collaboration, Apptio FinOps AI updates, and a $5 billion open source security commitment with Red Hat. ECI Research analysts break down what the announcements mean for ITDMs and developers navigating enterprise AI deployment. The pattern points toward infrastructure incumbents consolidating control over the agentic AI stack.

IBM’s Enterprise AI Push: Google, ServiceNow, Apptio & Red Hat Read More »

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom has released the largest Spring security update in the framework’s history, introducing commercial-first CVE-only patches and a SLSA Level 3-validated Java supply chain. AI-accelerated threat discovery has broken traditional patching cycles, and Broadcom’s response sets a new benchmark for open source stewardship under commercial cover. ECI Research examines what this means for enterprise risk posture, developer workflows, and the competitive landscape.

Broadcom Bets Big on Spring Ecosystem Security | ECI Research Read More »

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM and Red Hat have announced Project Lightwell, a $5 billion initiative pairing 20,000 engineers with AI to secure enterprise open source software at scale. The clearinghouse model targets supply chain vulnerabilities across independent libraries, AI frameworks, and data streaming platforms. ECI Research examines what this means for ITDMs and developers navigating an increasingly fragmented open source security landscape.

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale Read More »

Mythos and Open Source Security: What the Panic Gets Wrong

Mythos and Open Source Security: What the Panic Gets Wrong

AI-powered vulnerability tool Mythos has sparked alarm across the open source community, but the fear-mongering misses the point. ECI Research breaks down the real risk, the rational response, and why upstream contribution matters more than reactive security spending.

Mythos and Open Source Security: What the Panic Gets Wrong Read More »