Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] Update on reporting obligations for open source software stewards



On Sun, Sep 6, 2026 at 12:33 AM Scott Lewis <slewis@xxxxxxxxxxxxx> wrote:

Does it then apply to the oss projects that the steward is using/depending upon to provide that build server (eg. compilers, encryption, dependency mgmt systems, etc)?

No, this focuses strictly on severe incidents affecting infrastructure provided to stewarded projects. Not CVEs in the infrastructure's components. 

Huh?  The log4j vulnerability (e.g.) was a severe incident that affected much sw infrastructure...provided to projects of many kinds, build systems, etc...as well as many other kinds of components (open source and commercial).  I don't see how you can you separate 'infrastructure provided to stewarded projects' from 'infrastructure' in general.

No. log4j was a vulnerability, not an incident. An incident is when a vulnerability is actually exploited, or some other event occurs, resulting in a compromise or material disruption of the infrastructure. So in the log4j case, a steward would have notification requirements for a vulnerability if they were the steward of log4j AND were actively involved in its development. They would have a notification requirement of a severe incident if running an unpatched version of log4j caused a build server they provided to a project to be compromised.

Back to the top