Broadcom announces TrueSource, a portfolio of verifiably built open source software solutions for enterprise security and support.
Quiver AI Summary
Broadcom Inc. has launched TrueSource, a portfolio providing commercially supported open source software tailored for enterprises. TrueSource comprises Spring Enterprise, enhanced security for the Java ecosystem and other languages via TrueSource Trusted Artifacts, and TrueSource Data Services for essential database engines like PostgreSQL and MySQL. The offerings focus on secure, vetted software that is built and maintained by Broadcom engineers, addressing vulnerabilities proactively while collaborating with open source maintainers. With the backdrop of increasing AI-driven threats, Broadcom emphasizes the importance of human oversight in patching and remediation rather than relying solely on automated solutions, ensuring that security measures are both reliable and accountable. TrueSource is now available through tiered site licensing options.
Potential Positives
- Launch of TrueSource by Broadcom introduces a portfolio of commercially supported open source software, enhancing enterprise reliability and security.
- TrueSource offers proactive scanning and verification of patches by engineers, providing customers confidence in patch reliability.
- The introduction of TrueSource Data Services extends Broadcom's commitment to secure data engines, addressing critical operational concerns in enterprise applications.
- Broadcom's focus on collaboration with community maintainers strengthens the ecosystem and supports the integrity of open source software.
Potential Negatives
- Concerns about the safety of AI-generated patches were highlighted, indicating that current automated solutions may not be reliable without significant human oversight.
- The press release suggests a significant dependency on proactive, human-verified patching processes due to the risks associated with automated solutions, indicating potential vulnerabilities in software security management.
- The mention of a 1,700 percent surge in monthly security advisories within the Spring community may raise alarms about the overall security health of the software ecosystem Broadcom is managing.
FAQ
What is TrueSource by Broadcom?
TrueSource by Broadcom is a portfolio of verifiably built open source software solutions for enterprises, including support, artifacts, and data services.
How does TrueSource ensure security for open source software?
TrueSource uses curation by Broadcom engineers, upstream remediation, and automated scanning to maintain security and provide trusted patches for software.
What are TrueSource Trusted Artifacts?
TrueSource Trusted Artifacts are secure, clean-room builds of libraries across various ecosystems, including Java, Python, and Node.js, ensuring reliability and security.
What makes Spring Enterprise different in open source security?
Spring Enterprise provides human-verified patches, proactive scanning, and simultaneous updates across release lines, emphasizing accountability and extensive compatibility checks.
How can customers access TrueSource offerings?
TrueSource offerings like Spring Enterprise, Trusted Artifacts, and Data Services are available through simple, tiered site licensing options.
Disclaimer: This is an AI-generated summary of a press release distributed by GlobeNewswire. The model used to summarize this release may make mistakes. See the full release here.
$AVGO Insider Trading Activity
$AVGO insiders have traded $AVGO stock on the open market 149 times in the past 6 months. Of those trades, 1 have been purchases and 148 have been sales.
Here’s a breakdown of recent trading of $AVGO stock by insiders over the last 6 months:
- HENRY SAMUELI has made 0 purchases and 38 sales selling 1,436,208 shares for an estimated $500,006,153.
- MARK DAVID BRAZEAL (Chief Legal & Corp Affairs Ofc) has made 0 purchases and 48 sales selling 166,834 shares for an estimated $59,425,537.
- S. RAM VELAGA (President, ISG) has made 0 purchases and 21 sales selling 102,594 shares for an estimated $34,421,293.
- CHARLIE B KAWWAS (President, SSG) has made 0 purchases and 19 sales selling 74,834 shares for an estimated $24,418,944.
- KIRSTEN M. SPEARS (CFO & Chief Accounting Officer) has made 0 purchases and 18 sales selling 60,154 shares for an estimated $19,452,715.
- JUSTINE PAGE has made 0 purchases and 2 sales selling 3,620 shares for an estimated $1,311,269.
- GAYLA J DELLY has made 0 purchases and 2 sales selling 2,890 shares for an estimated $1,086,678.
- HARRY L. YOU purchased 1,000 shares for an estimated $373,570
To track insider transactions, check out Quiver Quantitative's insider trading dashboard. You can access data on insider stock transactions through the Quiver Quantitative API insider transaction endpoint.
$AVGO Revenue
$AVGO had revenues of $22.2B in Q2 2026. This is an increase of 47.87% from the same period in the prior year.
You can track AVGO financials on Quiver Quantitative's AVGO stock page.
You can access data on AVGO stock through the Quiver Quantitative API.
$AVGO Congressional Stock Trading
Members of Congress have traded $AVGO stock 8 times in the past 6 months. Of those trades, 3 have been purchases and 5 have been sales.
Here’s a breakdown of recent trading of $AVGO stock by members of Congress over the last 6 months:
- REPRESENTATIVE DAVID TAYLOR has traded it 3 times. They made 1 purchase worth up to $15,000 on 07/24 and 2 sales worth up to $30,000 on 04/27.
- REPRESENTATIVE RICK W. ALLEN purchased up to $15,000 on 07/14.
- SENATOR SHELLEY MOORE CAPITO sold up to $15,000 on 04/13.
- REPRESENTATIVE JARED MOSKOWITZ purchased up to $15,000 on 03/31.
- SENATOR ALAN ARMSTRONG sold up to $50,000 on 03/27.
- REPRESENTATIVE GILBERT RAY CISNEROS, JR. sold up to $15,000 on 03/25.
To track congressional stock trading, check out Quiver Quantitative's congressional trading dashboard. You can access data on congressional stock trades through the Quiver Quantitative API Congress trades endpoint.
$AVGO Hedge Fund Activity
We have seen 2,598 institutional investors add shares of $AVGO stock to their portfolio, and 2,147 decrease their positions in their most recent quarter.
Here are some of the largest recent moves:
- JPMORGAN CHASE & CO added 95,016,148 shares (+inf%) to their portfolio in Q2 2026, for an estimated $35,892,349,907
- INVESCO LTD. added 35,875,676 shares (+107.7%) to their portfolio in Q2 2026, for an estimated $13,552,036,609
- SIXTH STREET PARTNERS MANAGEMENT COMPANY, L.P. added 33,404,003 shares (+inf%) to their portfolio in Q2 2026, for an estimated $12,618,362,133
- FMR LLC added 20,246,297 shares (+16.3%) to their portfolio in Q2 2026, for an estimated $7,648,038,691
- BLACKROCK, INC. added 12,269,052 shares (+3.2%) to their portfolio in Q2 2026, for an estimated $4,634,634,393
- ARROWSTREET CAPITAL, LIMITED PARTNERSHIP removed 10,145,294 shares (-54.1%) from their portfolio in Q2 2026, for an estimated $3,832,384,808
- SG AMERICAS SECURITIES, LLC removed 7,595,730 shares (-35.6%) from their portfolio in Q2 2026, for an estimated $2,869,287,007
To track hedge funds' stock portfolios, check out Quiver Quantitative's institutional holdings dashboard. You can access data on hedge funds moves and 13F filings through the Quiver Quantitative API 13F endpoint.
$AVGO Analyst Ratings
Wall Street analysts have issued reports on $AVGO in the last several months. We have seen 2 firms issue buy ratings on the stock, and 0 firms issue sell ratings.
Here are some recent analyst ratings:
- Deutsche Bank issued a "Buy" rating on 06/04/2026
- UBS issued a "Buy" rating on 06/04/2026
To track analyst ratings and price targets for $AVGO, check out Quiver Quantitative's $AVGO forecast page.
$AVGO Price Targets
Multiple analysts have issued price targets for $AVGO recently. We have seen 21 analysts offer price targets for $AVGO in the last 6 months, with a median target of $525.0.
Here are some recent targets:
- Ross Seymore from Deutsche Bank set a target price of $515.0 on 06/04/2026
- Cody Acree from Benchmark set a target price of $545.0 on 06/04/2026
- Gil Luria from DA Davidson set a target price of $400.0 on 06/04/2026
- Arthur Lai from Macquarie set a target price of $437.0 on 06/04/2026
- Rick Schafer from Oppenheimer set a target price of $535.0 on 06/04/2026
- Vijay Rakesh from Mizuho set a target price of $530.0 on 06/04/2026
- Vivek Arya from B of A Securities set a target price of $530.0 on 06/04/2026
Full Release
LAS VEGAS, Aug. 31, 2026 (GLOBE NEWSWIRE) -- VMware Explore 2026 -- Broadcom Inc. (NASDAQ: AVGO), a global technology leader that designs, develops, and supplies semiconductor and infrastructure software solutions, today announced TrueSource by Broadcom, a portfolio of commercially supported, verifiably built open source software for the enterprise.
TrueSource brings together Spring Enterprise, the company’s flagship offering for the Spring ecosystem; new TrueSource Trusted Artifacts, which provides secure clean-room builds of the broader Java ecosystem, Python, and Node.js and incorporates a secure catalog of hardened container images; and TrueSource Data Services, a new offering that provides trusted artifacts, support, and deployment expertise for PostgreSQL, RabbitMQ, MySQL, and Valkey data engines.
TrueSource Offerings are Built on Common Principles
- Curated, prescriptive, enterprise-grade libraries and artifacts : Every library and artifact is selected against a reference architecture, built, and verified by Broadcom engineers, so enterprises consume open source with confidence.
- Remediation with maintainers, not around them : Broadcom contributes fixes upstream and backs community maintainers across the industry with engineering time and funding.
- Patch automation tooling and security visibility : Automation scans customer repositories, assesses the blast radius of each release before they consume it, and opens pull requests that apply the lowest-risk remediation path, with dashboards showing their security team exactly what’s fixed and what remains.
- Early access with collaboration: Properly licensed customers of any TrueSource offering will have the option to bring not-yet-public vulnerabilities they discover for early access to remediation. In addition, there is a special program for critical infrastructure organizations to get dedicated access to patch insights and mitigation advice.
Broadcom Sets the Enterprise Standard with Spring Enterprise
Building on Broadcom’s
June commitment to Spring supply chain security
, this announcement arrives as AI accelerates exploitation, allowing attackers to weaponize vulnerabilities in hours. While this has fueled interest in fully automated, AI-generated patching, research indicates this approach carries significant operational and security risks.
In new testing , 1Password’s Off-by-1 Labs found that only 26 percent of 6,000 AI-generated patches fixed vulnerabilities without breaking applications. They concluded that automated patches are not yet safe enough to trust without significant human oversight.
Spring Enterprise provides secure, curated releases of Spring from the team that creates and maintains it. That stewardship comes with over 20 years of experience in making compatibility, performance, and security judgements that have allowed Spring to flourish.
Customers receive:
- Proactive scanning with human-verified patches: Broadcom engineers continuously scan Spring and its dependency tree with frontier model analysis, then verify every patch by hand, finding vulnerabilities before attackers do. In the past five months, engineers have already spent more than 12 billion tokens against frontier models.
- Simultaneous patches across every release line : Because Broadcom maintains Spring, every supported release line is patched before a CVE is ever published. Disclosure and remediation for OSS and long term support versions arrive together, so no version is left waiting for a fix.
- The whole dependency tree, not just Spring : Coverage extends beyond Spring itself to its managed dependencies, including Apache Tomcat, Kotlin, and across the full dependency tree: more than 5,000 verified Java libraries, built and signed at the exact versions pinned by every supported Spring Boot release line.
- Security fixes without the upgrade : Full point releases bundle fixes with changes that demand testing. CVE-only patches carry the remediation alone, so security teams can push them to production in hours, not weeks.
"The world’s most essential businesses run on open source software, and they trust us to keep that foundation secure," said Ram Velaga, president, Infrastructure Software Group, Broadcom. "As AI accelerates both innovation and exploitation, that trust cannot rest on unverified, machine-generated patches. It has to rest on accountable engineering. With TrueSource, we are making a long-term commitment to our customers: our fixes are built and verified by our engineers, working alongside the maintainers who know the code best."
TrueSource Trusted Artifacts Extends Coverage Across Ecosystems
TrueSource Trusted Artifacts provides secure, clean room SLSA Build Level 3 builds of libraries across the Java ecosystem, Python, and Node.js. Broadcom’s curation process ensures that the libraries conform to a reference architecture and are supportable by the maintainers of record. Thousands of engineers across Broadcom’s software divisions scan, fix, contribute to, and consume them every day in the software that runs the world’s most essential businesses. The offering also includes the Bitnami Secure Images catalog, adding hardened, verifiably built container images for hundreds of commonly used open source packages to the same commercial offering.
TrueSource Data Services brings it to the data tier
TrueSource Data Services extends the TrueSource promise to the data engines enterprise applications depend on: PostgreSQL, RabbitMQ, MySQL, and Valkey. A flawed patch can put the data itself at risk, so remediation takes operational judgment. Broadcom brings that judgment, from hardening and supporting these engines for the world’s most demanding enterprises, to curate a validated distribution inclusive of these data engines and the associated critical extensions, Operators and Helm Charts. The offering includes deployment automation for these engines as well as visibility into the security and operational posture.
One Standard Across the Portfolio
The three offerings cover different ecosystems, but they share one design: software that is verifiably built, remediated by accountable engineers, and delivered in partnership with the communities that create it. "Open source security is a human discipline," said Purnima Padmanabhan, vice president and general manager, Tanzu Division, Broadcom. "AI is a phenomenal accelerant for the engineers who maintain this software, not a replacement for them. Maintainers understand the intent behind the code, and that is what separates a real fix from one that just looks like it. TrueSource puts that human expertise at the center of the open source supply chain, at commercial scale."
"AI-generated patching, when applied outside a maintained upstream project, risks producing forks that lack maintainer oversight and long-term accountability," said Katie Norton, Research Director for IDC’s Cloud Security research practice. "Broadcom’s approach with Spring, pairing upstream remediation with human-verified engineering, is one response to this trend, intended to support the integrity and sustainability of the open source supply chain."
Broadcom has already invested behind this position, applying AI where it is effective. As announced in June, its Spring engineering team has scaled frontier model based scanning and validation across the dependency ecosystem, with every resulting fix authored, reviewed, and verified by engineers who know the code. That work answered the more than 1,700 percent surge in monthly security advisories reported by the Spring community and delivered the largest set of security patches in Spring’s 23-year history.
Availability
Spring Enterprise, TrueSource Trusted Artifacts, and TrueSource Data Services are available with simple, tiered site licensing options.
About Broadcom
Broadcom Inc. (NASDAQ: AVGO) is a technology leader that designs, develops, and supplies semiconductors and infrastructure software for global organizations’ complex, mission-critical needs. Broadcom combines long-term R&D investment with superb execution to deliver the best technology, at scale. Broadcom is a Delaware corporation headquartered in Palo Alto, CA. For more information, visit
www.broadcom.com
.
Broadcom, the pulse logo, and Bitnami are among the trademarks of Broadcom. Postgres and PostgreSQL are registered trademarks of the PostgreSQL Community Association of Canada. MySQL is a registered trademark of Oracle Corporation. Valkey is a trademark of The Linux Foundation. All other trademarks are the property of their respective owners. Broadcom is not affiliated with, endorsed by, or sponsored by any of the foregoing organizations.
Media Contact:
John D’Avolio
Tanzu Division, Broadcom
+1.503.308.3096
[email protected]