The Linux Foundation has launched Akrites, a coordinated initiative to discover, remediate, and responsibly disclose vulnerabilities in critical open-source software. It brings together technology companies, AI laboratories, financial institutions, telecom operators, and security vendors.
One team and a standardised process
At its centre is a shared Security Incident Response Team and a single coordinated vulnerability disclosure process. Rather than overwhelming maintainers with duplicate or poorly coordinated reports, Akrites aims to consolidate reports confidentially, work with upstream projects, and coordinate patches with affected organisations.
The process uses established tools and standards including CVE, CWE, CVSS, EPSS, SSVC, and VEX. Founders are committing funding, engineering time, and expertise, while the initiative says it can act as a maintainer of last resort where a critical package no longer has active stewardship.
The Dimitrium view: shared dependency requires shared maintenance
Banks, hospitals, energy networks, telecoms, and governments share much of the same software foundation even when their products look unrelated. The failure occurs when everyone captures its value but responsibility for an emergency fix rests with one volunteer.
Akrites could fill an important coordination gap, but success should be measured by contributions that reach upstream communities. With transparent governance and respect for maintainers it can become a model for investing in infrastructure the market already treats as a public good.