Appendix: Lightwell concepts (FAQ distill)
Optional reference for instructors and learners. Distills technical concepts that appear in field Lightwell enablement into workshop language. It does not replace the seven gated tracks, and it omits commercial SKUs, pricing, competitor comparisons, and associate-only sales guidance.
Hands-on work stays in the core modules. Use this page when a learner asks “what does Validated mean?” or “does Lightwell go through Satellite?”
Product definition
| Question | Workshop answer |
|---|---|
What problem does Lightwell solve? |
Scanners/SBOMs find vulns; teams often cannot upgrade. Lightwell supplies surgical security backports on pinned versions. |
What is Lightwell Network vs Lightwell Clearinghouse Premier? |
Network (available) is catalog remediations: Validated and Remediated repos consumed through existing build and artifact-manager workflows. Clearinghouse Premier (limited availability) includes all Network benefits plus member-specific package versions, novel vulnerability verification and disclosure handling (secured patch embargoes), anonymized member requests, and TAM services. This lab scores the Network path. Premier remediations would use the same proxy, pin, hermetic build, and TPA ingest (workshop home). Product page: Lightwell. |
What is an embargo? |
A coordinated-disclosure window: the vulnerability and its patch stay in a closed member set until a public date. Premier can deliver a member-specific |
What is in scope? |
Signed remediations and supply-chain artifacts for eligible third-party application dependencies (libraries, frameworks, build tools, transitive deps), CVE triage metadata, SBOM/VEX, and related attestations. |
What is out of scope for this lab path? |
Proprietary code scanning, penetration testing, feature bug fixes, Satellite content views, inventing alternate channel names, a live Premier membership or member-specific GAV on this claim. |
Which ecosystems? |
Java (Maven) is the lab application. Python (PyPI) uses the same Validated / Remediated idea. Do not promise unannounced ecosystems. |
Repositories and versioning
| Question | Workshop answer |
|---|---|
Validated vs Remediated? |
Validated = upstream binaries, bit-for-bit, from a trusted Red Hat source, validated for known CVEs. Remediated = Red Hat security-only patches on a pinned baseline. Java uses |
When does Remediated become Validated? |
Only after upstream accepts, merges, and releases the fix; otherwise it stays Remediated. |
How do I find status? |
Console for Validated browse (https://console.redhat.com/lightwell). OSV metadata for Remediated CVE ↔ |
Are sources available? |
Yes—source archives ship beside binaries in the same repos (2.2 source diff). |
How are new packages noticed? |
Poll the OSV feed (optional PULP_MANIFEST automation). |
Integration
| Question | Workshop answer |
|---|---|
How do build tools integrate? |
2.1 (Maven scored; pip / Artifactory callouts). Artifactory map: remote to Lightwell URL, virtual for developers, include/exclude so Lightwell GAVs do not fall through to Central. |
Air-gapped? |
Same mirror/proxy patterns used for other Red Hat content—not a unique LWN-only protocol. |
Via Satellite? |
No. Consume via artifact repository infrastructure ( |
Non-RHEL runtimes? |
Yes—application-layer libraries can run on non–Red Hat OS/stacks. |
Customer testing? |
Red Hat runs upstream/regression checks before publish; application-context testing remains the consumer’s responsibility. |
OSV, SBOM, and pipelines
Acronym expansions: Acronym glossary. First teaching definitions also appear on the workshop home page.
| Question | Workshop answer |
|---|---|
OSV id shape? |
Production: |
Are AI models named in OSV? |
No—discovery source stays anonymous; credits identify Red Hat Lightwell as remediation developer. |
Compliance artifacts? |
SLSA L3, cryptographic signing (RHTAS-class), CycloneDX + VEX for Maven, SPDX for Python wheels. |
CI scanners (Snyk-class tools)? |
Consume OSV/VEX so Lightwell-patched CVEs are recognized as remediated (7.2). |
Proprietary source to Red Hat? |
No—manifests and SBOMs, not application source trees. |
Coexistence
| Question | Workshop answer |
|---|---|
vs RHEL / OpenShift / ACS? |
Complementary. Platform products cover OS/platform; Lightwell covers third-party app deps. 7.2 scores ACS with the remediated pin. |
vs Hardened Images? |
Hardened Images address container foundations; Validated/Remediated address application dependencies. |
vs TSSC (RHTAS, RHTPA, GitOps, Pipelines)? |
TSSC is the controls around the image (sign, SoR, admit, hermetic build). Lightwell Network (and Premier) is a trusted input those controls consume. Neither replaces the other. See workshop home. |
vs IBM LSOS? |
LSOS extends selected EOL Java frameworks; Lightwell backports across a broad catalog with registry/signing/SBOM story. Not exercised in this workshop. |
What we deliberately do not add as labs
The following FAQ topics stay out of the Showroom hands-on path:
-
Commercial STAM / Services Accelerator SKUs and pricing
-
Competitor positioning
-
International sales / export / federated clearinghouse policy
-
A live Clearinghouse Premier membership or embargo window on this RHDP claim (the TSSC controls Premier would reuse are Tracks 2, 3, and 7)
-
Live air-gap sync Job beyond the seeded/proxy modes already in 2.1
-
Embargo contract enforcement (legal / disclosure frameworks). The concept is on workshop home and 2.2.
Return to Workshop home or start 1.1.
