Hi all,
As agreed during today's call, please use this email thread to discuss topics for potential TF deliverables.
Here are some possible topics that were raised:
- A document describing the role and obligations of stewards
- Best current practise for SBOM in open source projects
- Describing the relation between open source projects and manufacturers in regards to vuln management
Additionally, it might be worth getting acquainted with the
deliverables plan as it contains a number of deliverables that might be interesting for this TF to get involved with or to drive.
Dear all,
I would like to propose a whitepaper the group can work on. According to my knowledge, no group (in ORC or otherwise) is working on this.
Proposal title: Open Source Software Stewards and CRA Whitepaper
Description:
The Cyber Resilience Act (CRA) defines a new category of organizations,
Open Source Stewards (Stewards hereafter). It also defines obligations
for them that are different from those of other categories like
manufacturers.This whitepaper will aim at elaborating on the obligations, restrictions, and penalties that will be imposed to Stewards.
From
the elaboration on the legal text, we will outline the missing pieces /
documents / procedures that Stewards need to have to fulfil their
obligations.
The
goal is NOT to provide a definition or guidance about who is and who is
not a steward for an Product with Digital Element qualifying as Open
Source Software.
Opinions?