---
格式版本: 2
标题: "Broadcom Strengthens Spring Security and Adds Coverage of Java, Python, and Node.js Ecosystems with TrueSource"
原文链接: "https://investors.broadcom.com/news-releases/news-release-details/broadcom-strengthens-spring-security-and-adds-coverage-java"
发布日期: "2026-08-31"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "LAS VEGAS, Aug. 31, 2026 (GLOBE NEWSWIRE) -- **VMware Explore 2026** -- Broadcom Inc. (NASDAQ: AVGO), a global technology leader that designs, develops, and supplies semiconductor and infrastructure software solutions, today announced TrueS"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 8
发布时间严格候选数量: 1
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-31T21:37:09+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-31T21:35:05+08:00"
入库时间: "2026-08-31T13:39:48.328Z"
来源平台: "Broadcom Investor News 搜索"
搜索渠道: "source_template"
搜索词: "https://investors.broadcom.com/?s=AI%20Rack"
匹配关键词:
  - "AI Rack"
  - "AI"
  - "deployment"
  - "performance"
相关厂家:
  - "Broadcom"
  - "Oracle"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI摘要: "Broadcom在VMware Explore 2026推出TrueSource产品组合，包含Spring Enterprise、TrueSource Trusted Artifacts和Data Services，为企业提供经人工验证。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-08-31T23:37:06.398Z"
AI优质: "否"
AI打分: 46
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "正文主线是Broadcom发布TrueSource开源软件供应链安全与商业支持产品，涉及Spring、Java、Python、Node.js及数据服务，并非超节点、AI Rack或机架级AI基础设施。来源为Broadcom官方投资者新闻稿，页面完整；新增事实包括TrueSource产品组合、SLSA Build Level 3构建、覆盖5000余个Java库及现已提供分级许可。固定知识库未显示该软件发布的历史重复，但未命中不能证明首次出现，且其新增内容不属于超节点业务。技术信息集中于软件补丁和制品安全，没有机架拓扑、互连、功耗、散热或RAS工程细节；命中主线弱相关强否决，当前页面不具备业务准入价值。"
AI质检模型: "gpt-5.6-sol"
AI质检时间: "2026-09-01T07:40:29+08:00"
AI主题相关性: 0
AI来源权威性: 15
AI新颖性: 13
AI技术细节: 2
AI商业部署信号: 6
AI完整性: 10
AI评分提示词版本: "v17-精简生产版"
AI评分提示词SHA256: "48fb9777f386026761b4873eaff30807694fb11e9b352d7c69bf2dfde750cc7d"
AI评分知识库版本: "knowledge_base_v1-20260819+runtime.63"
AI评分知识库SHA256: "b2a4248d43868dee4c86d2b502d43668e260aea6b69d15f73a5dfe53287ca63f"
AI评分知识库检索词: "[\"Broadcom\",\"AI Rack\",\"https://investors.broadcom.com/?s=AI%20Rack\",\"RAS\",\"PDF\",\"investors.broadcom.com/node/64651/pdf\",\"LAS\",\"VEGAS\",\"GLOBE\",\"NEWSWIRE\",\"VMware\",\"NASDAQ\"]"
AI评分知识库命中: "[{\"id\":\"historical-jun-042\",\"title\":\"AI Rack/机柜级超节点架构，详细列出Vera Rubin/GB200 NVL72规格、NVLink 6互连、HBM3e、液冷与供电设计，具备明确的产品化与\",\"sourceType\":\"curated_item\",\"time\":\"2026-06\",\"matchedTerms\":[\"AI Rack\"],\"rank\":-7.508186289472906},{\"id\":\"runtime-5581f72bc66fda8e6c6bf711\",\"title\":\"Advancing Standards-Based AI Fabric RAS Through COSMOS Integration\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-10\",\"matchedTerms\":[\"RAS\",\"PDF\"],\"rank\":-7.214927280537893},{\"id\":\"july-correct-0062\",\"title\":\"Why AI Racks Need an Open Signal Conditioning Standard\",\"sourceType\":\"labeled_article\",\"time\":\"2026-07\",\"matchedTerms\":[\"AI Rack\",\"RAS\",\"PDF\"],\"rank\":-6.916242094017264},{\"id\":\"historical-jun-010\",\"title\":\"爱建证券-电子行业专题报告：Vera Rubin量产提速，RTX Spark打开终端AI新空间-260608.pdf\",\"sourceType\":\"curated_item\",\"time\":\"2026-06\",\"matchedTerms\":[\"PDF\"],\"rank\":-6.104521873815825},{\"id\":\"runtime-0fa5f6513e1d75f79b9b89e6\",\"title\":\"https://www.datacenterknowledge.com/ai-data-centers/ai-rack-density-s-real-limits-power-cooling-failure-risk\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-28\",\"matchedTerms\":[\"AI Rack\",\"RAS\",\"PDF\",\"LAS\"],\"rank\":-6.06571958645285}]"
采集批次: "2026年8月31日21点29分41秒"
采集批次ID: "20260831-212941-844"
去重键: "https://investors.broadcom.com/news-releases/news-release-details/broadcom-strengthens-spring-security-and-adds-coverage-java"
---

View printer-friendly version

[PDF Version](https://investors.broadcom.com/node/64651/pdf)

### New Offerings Expand Open Source Coverage with an Extensive Catalog of Secure, Verifiably Built, Known-good Open Source Libraries and Images

LAS VEGAS, Aug. 31, 2026 (GLOBE NEWSWIRE) -- **VMware Explore 2026** -- Broadcom Inc. (NASDAQ: AVGO), a global technology leader that designs, develops, and supplies semiconductor and infrastructure software solutions, today announced TrueSource by Broadcom, a portfolio of commercially supported, verifiably built open source software for the enterprise.

TrueSource brings together Spring Enterprise, the company’s flagship offering for the Spring ecosystem; new TrueSource Trusted Artifacts, which provides secure clean-room builds of the broader Java ecosystem, Python, and Node.js and incorporates a secure catalog of hardened container images; and TrueSource Data Services, a new offering that provides trusted artifacts, support, and deployment expertise for PostgreSQL, RabbitMQ, MySQL, and Valkey data engines.

**TrueSource Offerings are Built on Common Principles**

- **Curated, prescriptive, enterprise-grade libraries and artifacts****:** Every library and artifact is selected against a reference architecture, built, and verified by Broadcom engineers, so enterprises consume open source with confidence.
- **Remediation with maintainers, not around them****:** Broadcom contributes fixes upstream and backs community maintainers across the industry with engineering time and funding.
- **Patch automation tooling and security visibility****:** Automation scans customer repositories, assesses the blast radius of each release before they consume it, and opens pull requests that apply the lowest-risk remediation path, with dashboards showing their security team exactly what’s fixed and what remains.
- **Early access with collaboration:** Properly licensed customers of any TrueSource offering will have the option to bring not-yet-public vulnerabilities they discover for early access to remediation. In addition, there is a special program for critical infrastructure organizations to get dedicated access to patch insights and mitigation advice.

**Broadcom Sets the Enterprise Standard with Spring Enterprise**  
Building on Broadcom’s [June commitment to Spring supply chain security](https://www.globenewswire.com/Tracker?data=FkZoyyozf5eJ_VstbHkkOPFw8QzfvhmhySDL9N7Fx00Wh3Eh7ekkbMbplOCEAal7vdp975hLjnAKkFthl0xyEXFO21XtCyuZ1AhaeFtlyYpIYxZ-cnVEQZCo11dzAIZ2DL5_ExxG5h9W0mQ37K5LowMHK1SV2LczTHu4F4keBEazmSH3MXY1WeVs3re_6e8x), this announcement arrives as AI accelerates exploitation, allowing attackers to weaponize vulnerabilities in hours. While this has fueled interest in fully automated, AI-generated patching, research indicates this approach carries significant operational and security risks.

In [new testing](https://www.globenewswire.com/Tracker?data=Weiws-dlK4ZhWwDclOStIwY7l_OWfqA4YYxQj6mB48cKumWtWG2FhRA7ZrEu5qaV-OybaxOGsDyd7uCcGMPg0kvRMFCnmIZZaJyV-os6S3BxUWUpO2Du7Wg2446ud68GLRruFDvEnjLZe-RPBFO2C90DEPXihahN27zqm-dIRAs=), 1Password’s Off-by-1 Labs found that only 26 percent of 6,000 AI-generated patches fixed vulnerabilities without breaking applications. They concluded that automated patches are not yet safe enough to trust without significant human oversight.

Spring Enterprise provides secure, curated releases of Spring from the team that creates and maintains it. That stewardship comes with over 20 years of experience in making compatibility, performance, and security judgements that have allowed Spring to flourish.

Customers receive:

- **Proactive scanning with human-verified patches:** Broadcom engineers continuously scan Spring and its dependency tree with frontier model analysis, then verify every patch by hand, finding vulnerabilities before attackers do. In the past five months, engineers have already spent more than 12 billion tokens against frontier models.
- **Simultaneous patches across every release line****:** Because Broadcom maintains Spring, every supported release line is patched before a CVE is ever published. Disclosure and remediation for OSS and long term support versions arrive together, so no version is left waiting for a fix.
- **The whole dependency tree, not just Spring****:** Coverage extends beyond Spring itself to its managed dependencies, including Apache Tomcat, Kotlin, and across the full dependency tree: more than 5,000 verified Java libraries, built and signed at the exact versions pinned by every supported Spring Boot release line.
- **Security fixes without the upgrade****:** Full point releases bundle fixes with changes that demand testing. CVE-only patches carry the remediation alone, so security teams can push them to production in hours, not weeks.

"The world’s most essential businesses run on open source software, and they trust us to keep that foundation secure," said Ram Velaga, president, Infrastructure Software Group, Broadcom. "As AI accelerates both innovation and exploitation, that trust cannot rest on unverified, machine-generated patches. It has to rest on accountable engineering. With TrueSource, we are making a long-term commitment to our customers: our fixes are built and verified by our engineers, working alongside the maintainers who know the code best."

**TrueSource Trusted Artifacts Extends Coverage Across Ecosystems**  
TrueSource Trusted Artifacts provides secure, clean room SLSA Build Level 3 builds of libraries across the Java ecosystem, Python, and Node.js. Broadcom’s curation process ensures that the libraries conform to a reference architecture and are supportable by the maintainers of record. Thousands of engineers across Broadcom’s software divisions scan, fix, contribute to, and consume them every day in the software that runs the world’s most essential businesses. The offering also includes the Bitnami Secure Images catalog, adding hardened, verifiably built container images for hundreds of commonly used open source packages to the same commercial offering.

**TrueSource Data Services brings it to the data tier**  
TrueSource Data Services extends the TrueSource promise to the data engines enterprise applications depend on: PostgreSQL, RabbitMQ, MySQL, and Valkey. A flawed patch can put the data itself at risk, so remediation takes operational judgment. Broadcom brings that judgment, from hardening and supporting these engines for the world’s most demanding enterprises, to curate a validated distribution inclusive of these data engines and the associated critical extensions, Operators and Helm Charts. The offering includes deployment automation for these engines as well as visibility into the security and operational posture.

**One Standard Across the Portfolio**  
The three offerings cover different ecosystems, but they share one design: software that is verifiably built, remediated by accountable engineers, and delivered in partnership with the communities that create it. "Open source security is a human discipline," said Purnima Padmanabhan, vice president and general manager, Tanzu Division, Broadcom. "AI is a phenomenal accelerant for the engineers who maintain this software, not a replacement for them. Maintainers understand the intent behind the code, and that is what separates a real fix from one that just looks like it. TrueSource puts that human expertise at the center of the open source supply chain, at commercial scale."

"AI-generated patching, when applied outside a maintained upstream project, risks producing forks that lack maintainer oversight and long-term accountability," said Katie Norton, Research Director for IDC’s Cloud Security research practice. "Broadcom’s approach with Spring, pairing upstream remediation with human-verified engineering, is one response to this trend, intended to support the integrity and sustainability of the open source supply chain."

Broadcom has already invested behind this position, applying AI where it is effective. As announced in June, its Spring engineering team has scaled frontier model based scanning and validation across the dependency ecosystem, with every resulting fix authored, reviewed, and verified by engineers who know the code. That work answered the more than 1,700 percent surge in monthly security advisories reported by the Spring community and delivered the largest set of security patches in Spring’s 23-year history.

**Availability**  
Spring Enterprise, TrueSource Trusted Artifacts, and TrueSource Data Services are available with simple, tiered site licensing options.

**About Broadcom**  
Broadcom Inc. (NASDAQ: AVGO) is a technology leader that designs, develops, and supplies semiconductors and infrastructure software for global organizations’ complex, mission-critical needs. Broadcom combines long-term R&D investment with superb execution to deliver the best technology, at scale. Broadcom is a Delaware corporation headquartered in Palo Alto, CA. For more information, visit [www.broadcom.com](https://www.globenewswire.com/Tracker?data=ULfCCv13AnzIkOiw3A1L291oSB2dmRQ78EBFtclNkUkgciVAUZgqluKtt5BKIb1MwX-7vt8PcC96DsTTL6xsiKedytfRHfmB9ONCpvMdmuk=).

*Broadcom, the pulse logo, and Bitnami are among the trademarks of Broadcom. Postgres and PostgreSQL are registered trademarks of the PostgreSQL Community Association of Canada. MySQL is a registered trademark of Oracle Corporation. Valkey is a trademark of The Linux Foundation. All other trademarks are the property of their respective owners. Broadcom is not affiliated with, endorsed by, or sponsored by any of the foregoing organizations.*

**Media Contact:**

John D’Avolio  
Tanzu Division, Broadcom  
+1.503.308.3096  
[john.davolio@broadcom.com](https://www.globenewswire.com/Tracker?data=6VvKI3vJ9f4vKoR9bkkpcnknGWcIQH2xvG8BM1Z-PhAepbXtJvcsIdvT2neA_h1yBlWcv7N8RfS7oGexFYXrDhF1BXfXwjkxgOrARD8Y8WXKLdpq-GZAKf4YV-MuQkzN)
