Akrites is building a shared defence for critical open-source software

The Linux Foundation is bringing companies, security experts, and maintainers together around a coordinated response to vulnerabilities in critical software infrastructure.

The Linux Foundation has launched Akrites, a coordinated initiative to discover, remediate, and responsibly disclose vulnerabilities in critical open-source software. It brings together technology companies, AI laboratories, financial institutions, telecom operators, and security vendors.

One team and a standardised process

At its centre is a shared Security Incident Response Team and a single coordinated vulnerability disclosure process. Rather than overwhelming maintainers with duplicate or poorly coordinated reports, Akrites aims to consolidate reports confidentially, work with upstream projects, and coordinate patches with affected organisations.

The process uses established tools and standards including CVE, CWE, CVSS, EPSS, SSVC, and VEX. Founders are committing funding, engineering time, and expertise, while the initiative says it can act as a maintainer of last resort where a critical package no longer has active stewardship.

The Dimitrium view: shared dependency requires shared maintenance

Banks, hospitals, energy networks, telecoms, and governments share much of the same software foundation even when their products look unrelated. The failure occurs when everyone captures its value but responsibility for an emergency fix rests with one volunteer.

Akrites could fill an important coordination gap, but success should be measured by contributions that reach upstream communities. With transparent governance and respect for maintainers it can become a model for investing in infrastructure the market already treats as a public good.

Source: Linux Foundation — Launch of Akrites