[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
[
List Home]
|
Re: [open-regulatory-compliance] Update on reporting obligations for open source software stewards
|
On 9/5/2026 12:39 PM, Tobie Langel
wrote:
On 9/5/2026 2:39 AM, Arnout Engelen wrote:
I read that to mean "the circumstances described in
Article 24(3)" (and I guess further guidance or
precedent that may come in the future).
Thanks. Here is Article 24(3) text:
3. The obligations laid down in Article 14(1) shall
apply to open-source software stewards to the extent that
they are involved in the development of the products with
digital elements. The obligations laid down in
Article 14(3) and (8) shall apply to open-source software
stewards to the extent that severe incidents having an
impact on the security of products with digital elements
affect network and information systems provided by the
open-source software stewards for the development of such
products.
[Scott] I would interpret this to say that the Article
14(1,3,8) obligations apply if severe incidents can affect
product security that use/depend upon oss...e.g.
frameworks/libraries/comm infrastructure/tools platforms,
etc.
1) Is that a correct interpretation, or does the legalese
restrict or broaden the scope beyond my interpretation?
2) If correct, my interpretation would suggest
a very broad application...e.g. any project (used/depended
upon by commercial systems) that has 'severe' security
implications on network and information systems (use
internet for install/update?). As an example: would this
include openssl, encryption impls, dependency mgmt
systems?
No, the only thing this is referring to is any
kind of infrastructure a steward is providing to the open
source project it is stewarding. Eg a build server.
Does it then apply to the oss projects that the steward is
using/depending upon to provide that build server (eg. compilers,
encryption, dependency mgmt systems, etc)?