Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[open-regulatory-compliance] Minutes from the due diligence meeting on 2026-09-24

Dear ORC Community,

find here the minutes of the Due diligence meeting held yesterday.

The main conversations we had were:
  • The team reviewed open pull requests and discussed due diligence frameworks for integrating Free and Open Source Software (FOSS) components under the Cyber Resilience Act (CRA).
  • Discussions covered going beyond basic attestations, the role of test data, and certification precedents like ISO 26262 and QNX to support manufacturer compliance.
  • Participants explored liability concerns under the Product Liability Directive (PLD) and the value of maintainer-manufacturer feedback, such as sharing usage data and contributing tests.
  • The group raised questions regarding specific due diligence records for downloading and verifying components.
Due diligence activities will follow-up by email in the next few weeks because the meeting on the 8th has been cancelled due to the multiple events happening on that day.

Have a great weekend.
Juan

--
Juan Rico
Senior Manager ORC, Oniro and Cloud Programs | Eclipse Foundation Europe GmbH | X | LinkedIn | YouTube | Instagram | Bluesky | Mastodon

Eclipse Foundation: The Community for Open Collaboration and Innovation



Berliner Allee 47, 64295 Darmstadt

Handelsregister: Darmstadt HRB 92821

Managing Directors: Gaël Blondelle, Mike Milinkovich, Michael Plagge


Back to the top