IBM と Red Hat、AI 時代のオープンソース信頼性強化へ Lightwell を拡張
本文の状態
日本語全文を表示中
詳細モードで約7分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
InfoQ AI/ML
IBM と Red Hat は、AI 支援開発時代における信頼できるソフトウェアサプライチェーン構築を目的として、Lightwell の新商用オファリングを発表し、署名や証明、ポリシー強制機能を統合したプラットフォームを提供する。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月11日 21:56
AI深層分析
キーポイント
Lightwell の商用拡大発表
IBM と Red Hat は、オープンソースプロジェクト Lightwell を基盤とした新商用オファリングを発表し、AI 時代における信頼性の高いソフトウェアサプライチェーン構築を支援する。
統合された信頼インフラの提供
署名、プロベナンス(由来)、アーティファクト検証、ポリシー強制といった機能を個別に扱うのではなく、これらを統合したプラットフォームとして提供し、人間および AI 生成コードの全ライフサイクルでの信頼性を確保する。
既存標準との連携と進化
Sigstore、in-toto、SLSA、SBOM といった近年出現したセキュリティ標準を踏襲しつつ、これらを単なる独立活動ではなく、ソフトウェアデリバリープロセスの各段階を検証可能な統合プラットフォームとして再構築する。
暗号化証明と継続的検証へのシフト
コードレビューや脆弱性スキャンに依存する従来のアプローチから脱却し、承認された環境でのビルド、信頼できるアイデンティティによる署名、未改変の証明といった暗号化証明と継続的検証を重視する。
暗号化証明と継続的検証への移行
信頼はリリース前の最終チェックではなく、開発からデプロイに至るまでソフトウェアに付随する属性となる。組織はコードレビューや脆弱性スキャンに加え、承認された環境での構築や署名の証拠を重視している。
重要な引用
Building on the open-source Lightwell project, the new offerings aim to simplify software signing, provenance, artifact verification, and policy enforcement
IBM argues that establishing a verifiable 'trust infrastructure' will become a foundational capability as enterprises increasingly rely on AI-generated code
Rather than relying solely on code reviews or vulnerability scanning, organizations are increasingly seeking evidence that software was built in approved environments
Rather than relying solely on code reviews or vulnerability scanning, organizations are increasingly seeking evidence that software was built in approved environments, signed using trusted identities, generated from verified source code, and has remained unaltered throughout its lifecycle.
編集コメントを表示
編集コメント
AI 生成コードの普及により、ソフトウェアの「どこから来たか」を証明する技術的・制度的基盤が急務となっている。IBM と Red Hat のこの動きは、散在するセキュリティ標準を実際の運用現場で即座に活用できる形へと昇華させる重要な一歩である。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
IBM と Red Hat は、AI を活用したソフトウェア開発の時代に向けて、信頼できる検証可能なソフトウェアサプライチェーンを構築するための新たな商用製品を発表しました。これにより、Lightwell オープンソースプロジェクトを基盤に、ソフトウェア署名、出所証明、アーティファクトの検証、ポリシー適用が簡素化され、人間と AI の双方によって生成されたソフトウェアが、デリバリーライフサイクル全体を通じて信頼できることを企業が確保できるようになります。
この発表は、ソフトウェアセキュリティにおける大きな転換点を示しています。AI がソフトウェア作成を加速する中、課題は単にコードを速く作るだけでなく、ソフトウェアの起源、構築方法、改変の有無、そして本番環境への展開前に組織のセキュリティポリシーに準拠しているかを証明することが求められています。IBM は、企業が AI 生成コードやオープンソースコンポーネント、自動化されたサプライチェーンへの依存を深める中で、検証可能な「信頼インフラ」の確立が基盤的な能力になると主張しています。
Lightwell は、過去数年間に登場した多くのセキュリティ標準を基盤としています。具体的には Sigstore、in-toto、SLSA (Software Artifacts のサプライチェーンレベル)、そして ソフトウェア部品表(SBOM) などのイニシアチブです。署名、出所証明、ポリシー適用をそれぞれ独立した活動として扱うのではなく、Lightwell はこれらを統合し、組織がソフトウェアデリバリープロセスのすべての段階を検証できる一貫性のあるプラットフォームを実現することを目指しています。
拡張された商用機能では、アーティファクトの署名、出所情報の生成、ポリシー検証、ライフサイクル管理が可能となり、企業は複数のバラバラなオープンソースプロジェクトを手作業で組み合わせる必要なく、サプライチェーンセキュリティを実装できます。これは特に、AI を活用した開発によって企業のデリバリーパイプラインに流入するソフトウェア変更の速度と量が増加している現状において、重要な意味を持ちます。
この動きにより、注目は暗号化による出所の証明と継続的な検証へと移っています。コードレビューや脆弱性スキャンだけに頼るのではなく、組織はソフトウェアが承認された環境で構築され、信頼できるアイデンティティによって署名され、検証済みのソースコードから生成され、ライフサイクルを通じて改ざんされていないという証拠を強く求めるようになっています。このモデルでは、信頼はリリース直前に行う最終的なセキュリティチェックではなく、開発からデプロイに至るまでソフトウェアに付随する属性となります。
全く新しいセキュリティ概念を導入するのではなく、Lightwell はこれらの新興規格の多くを商業サポート付きのプラットフォームとしてパッケージ化し、組織がエンタープライズ向けのソフトウェアデリバリー環境でより容易に採用できるようにしています。重点は既存のセキュリティコントロールを置き換えることではなく、日益複雑化する開発エコシステム全体で一貫して運用することにあります。
今回の発表は、ソフトウェアエンジニアリングにおける重要な進化も反映しています。従来、ソフトウェアサプライチェーンのセキュリティは、悪意のあるコードがビルドパイプラインに侵入するのを防ぐことに焦点を当てていました。しかし現在では、組織はソースコードだけでなく、AI 生成物、自動化されたワークフロー、インフラストラクチャの変更、そして自律的なソフトウェアデリバリープロセスへの信頼も確立する必要があります。
AI エージェントがコード生成、インフラの修正、インシデント対応、そしてソフトウェアデリバリーへの直接参加を可能にするようになると、組織は「誰(または何)が」「どのアイデンティティで」「どのようなポリシーに従って」各アクションを実行したかを検証する仕組みが必要になります。これは、より自律化するソフトウェアシステムを透明性と説明責任のあるものにするための業界全体の取り組み——検証可能な実行、暗号化アテスタション、ワークロードアイデンティティ、コードとしてのポリシーなど——と合致しています。
IBM と Red Hat は、信頼できるソフトウェアサプライチェーンへの広範な動きの一部です。GitHub は CodeQL やアーティファクトの証明(アテステーション)、シークレットスキャンを通じて証明機能を拡大し続けています。一方、Google は SLSA 枠組みと Sigstore の採用を自社のソフトウェアエコシステムで推進しています。Microsoft はソフトウェア署名と証明機能を Azure DevOps および GitHub Advanced Security に統合しました。また、Cloud Native Computing Foundation (CNCF) は最近 Kusari と提携し、クラウドネイティブプロジェクト全体のサプライチェーンセキュリティを強化しています。同時に、Linux Foundation の Akrites プロジェクトのようなイニシアチブでは、同様の暗号化された信頼モデルが、AI を活用した新たな脅威からオープンソースソフトウェアを守る方法を探っています。
これらの取り組みは実装方法こそ異なりますが、共通の目的を持っています。それは、ソフトウェアが単に正しく動作するから信頼できるのではなく、ソースコードからデプロイに至るまでのライフサイクル全体が検証可能で透明性があり、改ざんに対して耐性を持つことを保証することです。Lightwell はこの哲学を AI エラにも拡張し、ソフトウェア作成に関与する AI システムもまた、人間の開発者と同様に信頼の対象に含まれるべきだと認識しています。
IBM が Lightwell の機能を拡大させたことは、ソフトウェアセキュリティの未来が個々のセキュリティツールに依存するのではなく、ライフサイクル全体にわたる包括的な信頼アーキテクチャにかかっていることを示唆しています。AI による開発加速と自動化の自律化が進む中、組織はあらゆる成果物や依存関係、デプロイメントを検証済みのソースまで遡って追跡でき、組織の方針に対して妥当性が確認できるという強力な保証を必要としています。
著者について
クレイグ・リーシ
クレイグ・リーシは多才な人物ですが、その才能の使い道に迷うこともあります。世界を変える活動をするよりも、ソフトウェアを作ることを好んでいます。彼はソフトウェアデザインへの情熱を持っていますが、それ以上に重要視するのは技術的に多様で絶えず進化を続けるテックの世界において、ソフトウェア品質とシステム設計に取り組むことです。
クレイグはまた、『Quality By Design: Designing Quality Software Systems』の著者であり、自身のブログサイトや世界のさまざまなテックメディアに定期的に記事を寄稿しています。
ソフトウェアをいじる時間がないときは、文章を書いたり、ボードゲームのデザインをしたり、理由もなく長距離走を楽しんだりしています。
原文を表示
IBM and Red Hat haveannounced an expansion of Lightwell, introducing new commercial offerings designed to help organizations establish trusted, verifiable software supply chains for the age of AI-assisted software development. Building on the open-source Lightwell project, the new offerings aim to simplify software signing, provenance, artifact verification, and policy enforcement, enabling enterprises to ensure that both human- and AI-generated software can be trusted throughout the software delivery lifecycle.
The announcement reflects a growing shift in software security. As AI accelerates software creation, the challenge is no longer simply producing code faster, but proving where software originated, how it was built, whether it has been modified, and whether it complies with organizational security policies before reaching production. IBM argues that establishing a verifiable "trust infrastructure" will become a foundational capability as enterprises increasingly rely on AI-generated code, open-source components, and automated software supply chains.
Lightwell builds upon many of the security standards that have emerged over the past several years, including Sigstore,in-toto, SLSA (Supply-chain Levels for Software Artifacts), and software bill of materials (SBOM) initiatives. Rather than treating signing, provenance, and policy enforcement as independent activities, Lightwell aims to integrate them into a cohesive platform that enables organizations to verify every stage of the software delivery process.
The expanded commercial offerings provide capabilities for artifact signing, provenance generation, policy validation, and lifecycle management, helping organizations implement supply chain security without assembling multiple disconnected open-source projects themselves. This is particularly relevant as AI-assisted development increases both the speed and volume of software changes entering enterprise delivery pipelines.
This has shifted attention toward cryptographic provenance and continuous verification. Rather than relying solely on code reviews or vulnerability scanning, organizations are increasingly seeking evidence that software was built in approved environments, signed using trusted identities, generated from verified source code, and has remained unaltered throughout its lifecycle. In this model, trust becomes an attribute that accompanies software from development through deployment rather than a final security check performed immediately before release.
Rather than introducing entirely new security concepts, Lightwell packages many of these emerging standards into a commercially supported platform that organizations can adopt more easily within enterprise software delivery environments. The emphasis is less on replacing existing security controls than on operationalizing them consistently across increasingly complex development ecosystems.
The announcement also reflects an important evolution in software engineering. Traditionally, software supply chain security focused on preventing malicious code from entering build pipelines. Increasingly, however, organizations need to establish trust not only in source code but also in AI-generated artifacts, automated workflows, infrastructure changes, and autonomous software delivery processes.
As AI agents become capable of generating code, modifying infrastructure, resolving incidents, and contributing directly to software delivery, organizations need mechanisms to verify who, or what, performed each action, under which identity, and according to which policies. This aligns with broader industry efforts around verifiable execution, cryptographic attestations, workload identity, and policy-as-code, all of which seek to make increasingly autonomous software systems transparent and accountable.
IBM and Red Hat are part of a much broader movement toward trusted software supply chains. GitHub has continued expanding provenance capabilities throughCodeQL, artifact attestations, and secret scanning, while Google has driven adoption of SLSA and Sigstore across its software ecosystem. Microsoft has integrated software signing and provenance into Azure DevOps and GitHub Advanced Security, and theCloud Native Computing Foundation (CNCF) recently partnered with Kusari to strengthen supply chain security across cloud-native projects. Meanwhile, initiatives such as theLinux Foundation's Akritesproject are exploring how similar cryptographic trust models can protect open-source software from emerging AI-enabled threats.
Although these initiatives differ in implementation, they share a common objective: ensuring that software can be trusted not simply because it functions correctly, but because its entire lifecycle, from source code to deployment, is verifiable, transparent, and resistant to tampering. Lightwell extends this philosophy into the AI era by recognising that trust must increasingly encompass not only human developers but also AI systems participating in software creation.
IBM's expansion of Lightwell suggests that the future of software security will depend less on individual security tools and more on comprehensive trust architectures that span the entire software lifecycle. As AI accelerates development and automation becomes increasingly autonomous, organizations will need stronger guarantees that every artifact, dependency, and deployment can be traced back to a verified source and validated against organizational policy.
About the Author
Craig Risi
Craig Risi is a man of many talents but has no sense of how to use them. He could be out changing the world but prefers to make software instead. He possesses a passion for software design, but more importantly software quality and designing systems in a technically diverse and constantly evolving tech world.
Craig is also the writer of the book, Quality By Design: Designing Quality Software Systems, and writes regular articles on his blog sites and various other tech sites around the world.
When not playing with software, he can often be found writing, designing board games, or running long distances for no apparent reason.
Show moreShow less
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み