Broadcom pledges to lock down open source Python, Java libraries
- ID
- 19976
- Status
- summarized
- Published
- 01 Sep 2026, 12:32 AM
- Fetched
- 01 Sep 2026, 4:50 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/virtualization/2026/08/31/broadcom-pledges-to-lock-down-open-source-python-java-libraries/5293454
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 01 Sep 2026, 4:51 AM
- Tags
- Audience
- developerssaas_founders
What happened
Broadcom announced 'TrueSource by Broadcom' ahead of VMware Explore, pledging to curate and secure open-source libraries that its Tanzu suite depends on—primarily Spring, RabbitMQ, and extending to wider Java, Python, and Node.js ecosystems. Purnima Padmanabhan, VP of Broadcom's Tanzu Division, says the company will provide 'trusted artifacts' that conform to a reference architecture and are supportable by maintainers of record.
Why it matters
This is a vendor tying open-source security curation to its commercial Tanzu Platform—unless you're a Tanzu customer or heavily invested in Spring/RabbitMQ, there's no action to take. The broader promise for Python and Node.js 'trusted artifacts' is vague on scope, timeline, and whether it will be available outside Tanzu subscriptions.
Discussion angle
Whether vendor-curated 'secure artifacts' for open-source dependencies is a genuine supply-chain improvement or a lock-in play—especially given Broadcom's post-VMware-acquisition reputation for squeezing customers.