Broadcom Pledges to Lock Down Open Source Python, Java Libraries (theregister.com) 7
Broadcom is launching "TrueSource," an effort to curate and secure open-source components used with its Tanzu platform, including Spring, RabbitMQ, and libraries across Java, Python, and Node.js. "The idea is to provide a set of solutions focused on providing clean and secure artefacts," Purnima Padmanabhan, vice president of Broadcom's Tanzu Division, told The Register. "We choose and build every Spring library, databases, other Java components," she said. The Register reports: Padmanabhan said that promise means VMware will also provide "TrueSource trusted artifacts" for code that is not part of Spring, including the wider Java ecosystem, Python, and Node.js. "Broadcom's curation process ensures that the libraries conform to a reference architecture and are supportable by the maintainers of record," according to a company statement. "Thousands of engineers across Broadcom's software divisions scan, fix, contribute to, and consume them every day."
A VMware spokesperson told The Register the Broadcom business unit "will work with and support maintainers on open source software and we will provide fixes to open source upstream for any active projects." "With Spring and RabbitMQ, we are the maintainers. For other open source software, we will work with the maintainers. We believe that the community maintainers must remain the source of truth," the spokesperson said.
This is just the sort of contribution that the open-source community wants vendors to do to reflect the value they extract from software they did not create alone. It's also the sort of thing vendors sometimes conclude they need to do to keep products based on FOSS viable.
A VMware spokesperson told The Register the Broadcom business unit "will work with and support maintainers on open source software and we will provide fixes to open source upstream for any active projects." "With Spring and RabbitMQ, we are the maintainers. For other open source software, we will work with the maintainers. We believe that the community maintainers must remain the source of truth," the spokesperson said.
This is just the sort of contribution that the open-source community wants vendors to do to reflect the value they extract from software they did not create alone. It's also the sort of thing vendors sometimes conclude they need to do to keep products based on FOSS viable.
Here We Go Again (Score:5, Insightful)
Another walled garden. That's a no thanks from me.
From Broadcom. That's a fuck off and die from me.
If you use Broadcom software and have a negative experience, you can only blame yourself.
I'll take the high road for once (Score:2)
and say this sounds like a very good thing, on the surface
Re:I'll take the high road for once (Score:4, Insightful)
It's the final round of... (Score:2)
...the competition for worst company in tech
In this corner, Apple
In this corner, Broadcom
Apple?!?! (Score:3)
With choices like Broadcom, Oracle, SCO, Meta, Microsoft and many more, how could you bring Apple into that ring?
Buy A Mirror. (Score:3)
Broadcom is launching "TrueSource,"..
The VMWare murderer needs to invest in a fucking mirror and read the damn room.
As if they can sell their True intent to anyone but an investor armed with fucking fangs these days.
Re: (Score:3)
Yeah, the company that killed VMWare is in no position to be deciding which open source software is acceptable and which is not. They'll probably (in time) require a payment for a positive review - and pretend to cover their asses by requiring payment for a review at all, but out of the theoretical kindness of their hearts, they'll do free reviews that all just happen to come out negative. Anyone who walks into this trap after knowing what they did to VMWare gets what they deserve.