---
title: "RedMonk Quick Take: VMware Explore 2026"
date: 2026-09-10T16:07:15Z
modified: 2026-09-10T16:07:15Z
permalink: "https://redmonk.com/videos/qt-vmware-explore-2026/"
type: video
status: publish
excerpt: ""
wpid: 5252
series:
  - Redmonk Quick Take
featured_image: "http://redmonk.com/wp-content/uploads/2026/09/Rachel-VMware-Explore-2026-1.png"
timestamp: 2026-09-10T16:07:15Z
tags:
  - Redmonk Quick Take
---

RedMonk’s Rachel Stephens sits down at VMware Explore to discuss the TrueSource by Broadcom announcement. Frontier models like Anthropic’s Mythos are finding vulnerabilities faster than enterprises can fix them, and neither enterprises nor upstream maintainers are prepared for the onslaught of reports and patches. TrueSource by Broadcom brings together a set of products to help enterprises handle this new reality, including TrueSource Trusted Artifacts, a new service that helps patch open source dependencies for Java, Python, and Node.js. The TrueSource umbrella also includes Spring Enterprise, Bitnami Secure Images, and TrueSource Data Services. RedMonk is watching with interest how commercial offerings like TrueSource can partner with open source communities so everyone ends up better protected.

This RedMonk video is sponsored by VMware by Broadcom.

**Links**

– [TrueSource by Broadcom announcement](https://www.broadcom.com/company/news/articles/vmware-explore/speed-is-the-problem-quality-early-access-truesource-broadcom)

## Transcript

Rachel Stephens (00:02)
I’m Rachel Stephens with RedMonk joining you today from VMware Explore. This show is definitely catered in general towards kind of that vSphere admin or operator persona. But the announcement that caught my attention and that I wanted to share with you all today actually came out of their application team. And the umbrella brand, I think is the best way to put it, is called TrueSource by Broadcom. And as I said, not a SKU, but rather a collection of products that are all about trying to bring trusted artifacts into the builds of developers and agents. some of these products already exist within the VMware portfolio. Some are there but maybe not well understood. And then others are new capabilities that the team is bringing together.

And the reason I want to focus this announcement is I think as broader industry implications around open source. And I think rather than diving into the specifics of what TrueSource by Broadcom is, I think it’s maybe more interesting to start with the why. And I think the why really stems from where we’re at as an industry with frontier models. Frontier models in general but also Mythos in particular, I think we saw that there’s just this general ratcheting up of the vulnerabilities that each new generation of model can find in our infrastructure and this general concern from enterprises that the capability to find vulnerabilities is outstripping the ability to actually address them. And so the industry overall has been trying to figure out ways that we can handle this.

And if you are a developer, maybe you’re thinking to yourself

“We have open source for a reason, why not just interact directly with the upstream?” I think there’s a few reasons why that doesn’t work from both perspectives of both the enterprises and the maintainers. From the enterprise side, a lot of enterprises don’t have the scale or the ability to both report vulnerabilities or to offer patches. Sometimes, in some cases, the act of reporting alone can reveal more about an enterprise’s infrastructure than they maybe feel comfortable with. So maybe it both reveals an attack vector. But also maybe just shares more about the state of their infrastructure than they are comfortable with. And so the idea of publicly reporting a vulnerability is unpalatable to a lot of enterprises. especially when you’re trying to think about doing that at scale of all of the different vulnerabilities that they can be finding. And so the idea of having a third party that they know how to work with a be able to help them remediate, patch and also responsibly disclose all these things is really appealing from the enterprise perspective. and from the maintainer perspective, what’s intriguing is having somebody who is not just going to find the issues but also help you patch the issues.

And not just with AI slop, but in a way that actually addresses the primary concern in a sustainable way, that’s really appealing for a lot of maintainers as well. And so kind of trying to meet the needs of both parties needs an intermediary. And this intermediary isn’t just VMware, to be clear. Like there’s definitely other motions in the market right now. We’ve seen the Athena Consortium kind of coalesce around Chainguard. We’ve seen IBM slash Red Hat and their Lightwell product. So we’ve seen other people in the market try to move in this direction.

What’s interesting about the way VMware is doing this is that they are trying to provide the depth of their expertise as the anchor point. So VMware is exceptionally well versed in the Spring and SpringBoot ecosystems, the Java ecosystems, because of their maintainership of those projects And the way that it works is yes, VMware is scanning for the vulnerabilities themselves. So scanning and patching the things that they find on their own. And then also everyone who’s a license holder can come in and report their vulnerabilities to VMware. VMware can help them patch them and report them and have responsible disclosure around them. And on top of all of this if you’re a license holder, you have a thirty day window to patch prior to public release of the CVE So you as an enterprise have a chance to be able to patch all of your own infrastructure so that you can avoid a zero day. because you’re already going to be patched when this gets released. And so these are some really substantial benefits to people. And so if you’re thinking about TrueSource by Broadcom, it’s kind of this combination of things that have already existed.

So we have Spring Enterprise, that’s a pretty well known entity. You have the Bitnami Secure Image Catalog of hardened container images. You have this new capability of vulnerability finding and disclosure and patching with the Trusted Source Artifacts. And then we also have the data services, which is the part that I had mentioned before that I think is undersung.

TrueSource Data Services takes some of the existing VMware capabilities around providing support for open source data services and kind of folds them into this entire story. So it’s not just that you’re protecting your applications but also the data services around them. In particular, the ones that they are focused on right now are Postgres MySQL, Valkey, and also RabbitMQ. So trying to make it so that if you are running these open source data services on your own rather than having to be in charge of maintaining them patching them solo you can work with Broadcom to make sure that it is easier and that these vulnerabilities are patched and fixed.

What I think is interesting about all of this is that there’s clearly a gap that exists in the market right now between what it means to have a vulnerability, to find a vulnerability, and to patch and remediate a vulnerability. And it’s really hard for enterprises to kind of make their way through this journey, and they are looking for support in the process to do that. That is what TrueSource by Broadcom is trying to address here. I think what’s really interesting is seeing how the market responds to these third party services, trying to provide support that bridges the gap between these needs and trying to figure out what that looks like from the combination of a commercial offering and an open source ecosystem and how they all merge together and hopefully what comes to be one cohesive movement where everybody can be better protected together.