Aikido acquires Root to revolutionize open source supply chain security

post-title

In a move to tackle the escalating threat of software supply chain attacks, Aikido has acquired Root, a pioneer in AI-driven vulnerability patching.

With attackers exploiting nearly a third of known vulnerabilities on or before disclosure day –and legacy issues like Log4Shell still lingering in millions of systems – Root’s agent-native approach generates precise, non-breaking CVE patches at machine speed, producing hundreds of verified fixes daily.

A new era for open source security
Traditional solutions force teams into impossible choices: risk breaking production with upgrades, migrate to locked-down vendor replacements, or ignore vulnerabilities entirely.

Root’s technology eliminates this dilemma by patching existing software versions in place, without migration or downtime.

“The industry is stuck in triage mode, debating which CVEs to fix first”, says Ian Riopel, Root’s CEO. “We built Root to skip the debate and just fix the problem – keeping open source secure and accessible.”

Aikido integrates Root’s capabilities
Aikido is launching Aikido Libraries and Aikido Images, offering vulnerability-free, drop-in replacements for existing dependencies and container images.

These solutions are already in production and available to all Aikido customers, ensuring continuous protection without breaking changes. Critically, fixes for actively exploited vulnerabilities will remain open source, contributed upstream to strengthen the entire ecosystem – not just Aikido’s customers.

A shared mission to empower developers
The acquisition unites Root’s team, including co-founders Ian Riopel, John, Benji, and Mickey, with Aikido’s vision to free developers from security fire drills.

“Open source maintainers are drowning in security work”, notes Adrian Estrada, CTO of NodeSource and OpenJS Board Director. “Aikido and Root are lightening the load by backporting fixes upstream.”

Together, they aim to restore focus on innovation, ensuring developers can build without the constant threat of supply chain attacks.

Related articles

Top