[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
[
List Home]
|
Re: [open-regulatory-compliance] Update on reporting obligations for open source software stewards
|
On 9/5/2026 3:45 PM, Tobie Langel
wrote:
Does it then apply to the oss projects that
the steward is using/depending upon to provide
that build server (eg. compilers, encryption,
dependency mgmt systems, etc)?
No, this focuses strictly on severe incidents
affecting infrastructure provided to stewarded
projects. Not CVEs in the infrastructure's
components.
Huh? The log4j vulnerability (e.g.) was a severe
incident that affected much sw infrastructure...provided
to projects of many kinds, build systems, etc...as well
as many other kinds of components (open source and
commercial). I don't see how you can you separate
'infrastructure provided to stewarded projects' from
'infrastructure' in general.
No. log4j was a vulnerability, not an incident.
LOL! I don't think that distinction would have mattered to my
employer at the time (a manufacturer using log4j for its
world-wide financial services, as well as it's build/deploy
infrastructure).