SBOM

Eclipse Foundation & OWASP Unite for CRA Open Source Security

Eclipse Foundation & OWASP Unite for CRA Open Source Security

The Eclipse Foundation and OWASP have signed an MOU to strengthen open source security and support EU Cyber Resilience Act compliance. With mandatory reporting obligations taking effect September 11, 2026, the partnership targets SBOM adoption, supply chain security, and maintainer readiness. ECI Research data shows supply chain security is a top-12-month investment priority for nearly half of enterprise respondents.

Eclipse Foundation & OWASP Unite for CRA Open Source Security Read More »

The 2026 Artifact Management Enforcement Gap | ECI Research

The 2026 Artifact Management Enforcement Gap | ECI Research

Cloudsmith’s second annual Artifact Management Report finds that AI-generated code has become near-universal, but governance hasn’t kept pace. Three in four organizations generate SBOM data without using it for real-time security enforcement. ECI Research examines what the EU Cyber Resilience Act deadline means for teams still relying on manual remediation.

The 2026 Artifact Management Enforcement Gap | ECI Research Read More »

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary Free AI-Powered Linux Security for AlmaLinux

Codenotary has launched a permanently free tier of its AI-powered security platform for AlmaLinux, covering up to 25 machines with full feature access. The offer includes SBOM management, CIS compliance, patch management, and AI agent monitoring. It’s a freemium land-and-expand play targeting lean ops teams with growing AI exposure.

Codenotary Free AI-Powered Linux Security for AlmaLinux Read More »

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus is opening its entire catalog of near-zero CVE container images for free, with no registration required. ECI Research examines why the move targets the growing asymmetry between AI-accelerated vulnerability discovery and slow remediation, and what it means for enterprise DevSecOps strategy. Signed SBOMs and an agent-ready CLI make this more than a freemium play.

Minimus Opens Free Secure Container Image Catalog | ECI Research Read More »

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

The Eclipse Foundation and ORC Working Group have launched the ORC Learning Hub, a free modular training platform helping developers, maintainers, and security teams prepare for the EU’s Cyber Resilience Act. With the first CRA obligations taking effect in September 2026, the initiative addresses a critical gap in role-specific compliance education for open source software supply chains. ECI Research analysts assess what this means for ITDMs and engineering teams navigating the new regulatory landscape.

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance Read More »

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom has released the largest Spring security update in the framework’s history, introducing commercial-first CVE-only patches and a SLSA Level 3-validated Java supply chain. AI-accelerated threat discovery has broken traditional patching cycles, and Broadcom’s response sets a new benchmark for open source stewardship under commercial cover. ECI Research examines what this means for enterprise risk posture, developer workflows, and the competitive landscape.

Broadcom Bets Big on Spring Ecosystem Security | ECI Research Read More »

SolidRun + Peridio: Closing the Physical AI Deployment Gap

SolidRun + Peridio: Closing the Physical AI Deployment Gap

SolidRun and Peridio have combined purpose-built vision AI hardware with a production-grade OS to address the infrastructure gap between prototype and deployed fleet. The integration delivers atomic OTA updates, SBOM support, and EU Cyber Resilience Act alignment as day-one capabilities. For enterprise buyers, this shifts physical AI deployment from a months-long infrastructure project to a weeks-long integration effort.

SolidRun + Peridio: Closing the Physical AI Deployment Gap Read More »

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale

IBM and Red Hat have announced Project Lightwell, a $5 billion initiative pairing 20,000 engineers with AI to secure enterprise open source software at scale. The clearinghouse model targets supply chain vulnerabilities across independent libraries, AI frameworks, and data streaming platforms. ECI Research examines what this means for ITDMs and developers navigating an increasingly fragmented open source security landscape.

IBM & Red Hat Project Lightwell: Open Source Supply Chain Security at Scale Read More »

AI Is Stressing Open Source Infrastructure | ECI Research

AI Is Stressing Open Source Infrastructure | ECI Research

AI-assisted contributions are surging into open source projects like Valkey, creating review burdens that are burning out maintainers faster than tooling can compensate. Meanwhile, package registries built for human-scale consumption are now serving machine-scale AI and CI workloads, straining the economics of critical software infrastructure. ECI Research examines what this means for enterprise risk, developer strategy, and the future of open source sustainability.

AI Is Stressing Open Source Infrastructure | ECI Research Read More »

GitLab 19.0: Agentic DevSecOps and the AI Paradox

GitLab 19.0: Agentic DevSecOps and the AI Paradox

GitLab 19.0 addresses the AI Paradox: code generation has accelerated, but credential governance, merge workflows, and pipeline security have not kept pace. The release embeds agentic capabilities and unified secrets management directly into the platform where teams already work. ECI Research breaks down what this means for ITDMs and developers evaluating DevSecOps platform consolidation.

GitLab 19.0: Agentic DevSecOps and the AI Paradox Read More »