Urgent.News

What's breaking now, across thousands of outlets.

Tech

Akrites: How the Linux Foundation Initiative Targets Open-Source Vulnerability Response

The Linux Foundation has launched Akrites , an initiative intended to coordinate vulnerability discovery, remediation and disclosure for critical open-source software. The project arrives as AI-enabled vulnerability scanning changes the scale at which potential software flaws can be identified. Its central emphasis is not simply finding more issues, but getting fixes made upstream and patches…

The Linux Foundation has introduced Akrites, an initiative aimed at coordinating the discovery, remediation, and disclosure of vulnerabilities in critical open-source software. As AI-driven vulnerability scanning enhances the scale at which potential software flaws can be identified, Akrites emphasizes not just finding more issues, but ensuring fixes are made upstream and patches are deployed.

The project is structured around a multi-stakeholder coalition comprising technology vendors, financial institutions, and open-source foundations. The initiative officially launched on June 25, 2026, and is coordinated by the Linux Foundation. The public letter, which includes organizations such as AWS, Anthropic, Chainguard, Cisco, Citi, Google, Microsoft, GitHub, JPMorganChase, IBM, NVIDIA, OpenAI, Endor Labs, Red Hat, the Rust Foundation, Sonatype, Vodafone, and Zscaler, emphasizes the importance of upstream fixes and patch deployment.

Akrites focuses on a practical security lifecycle, moving beyond the early stage of vulnerability discovery to the crucial stages of remediation and disclosure. The coalition comprises cloud, software, and security vendors, AI and developer-security companies, open-source foundations and communities, and organizations that rely on software supply chains.

While the letter lists around 25 to 30 organizations, Akrites is narrower in scope than a broad regulatory or cross-sector cyber-defense campaign. Its primary goal is to coordinate work on critical open-source software vulnerabilities, aligning organizations around the operational stages that follow discovery. For businesses utilizing software built on open-source components, Akrites underscores that vulnerability management extends beyond purchasing scanning tools.

It highlights the importance of understanding whether issues are remediated upstream and if relevant patches are deployed. Businesses should prioritize validating findings before generating remediation work, ensuring upstream remediation for open-source issues, determining who is responsible for assessing and deploying patches, and measuring progress through resolved and deployed fixes rather than merely the number of identified issues.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Your Codebase Doesn't Need AI. It Needs Context.

Every hackathon has the same 90-second moment of dread: someone hands you a codebase you've never seen, and you have to make sense of it before the clock runs out. File trees don't help.

  • Waypoint platform generates Mission Brief for new codebases
  • Visual tools include Architecture Map and Dependency Galaxy

Govt Gives Tiny Relief in Fuel Prices

The federal government has decided to decrease the prices of motor spirit (MS) petrol and high-speed diesel (HSD) for the … Read More The post Govt Gives Tiny Relief in Fuel Prices appeared first on…

More from Thursday 27 August →