The "good" people at Emerson for some reason couldn't think for themselves when I responded to them on behalf of #curl and instead continue and send the same questions to the #libssh2 project with the same "demands".
"This is a gentle reminder regarding our earlier request for your input on the cybersecurity risk assessment of the software component βlibssh2β version 1.11.0, as part of our compliance efforts with the EU Cyber Resilience Act (CRA)."
Robin Whittleton
in reply to daniel:// stenberg:// • • •synlogic
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to daniel:// stenberg:// • • •synlogic
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Simon Michalke
in reply to daniel:// stenberg:// • • •Fubaroque
in reply to daniel:// stenberg:// • • •Thomas Svensson π
in reply to daniel:// stenberg:// • • •Much depends on how serious EU will be about enforcing this new regulation. I they don't, then these guys likely keep using in violation.
I'm loading up with πΏ
Miketlester
in reply to daniel:// stenberg:// • • •Please forward the actual email thread to Michael.lester@emerson.com
Emerson appreciates the OSS community.
Jeroen van Bergen
in reply to daniel:// stenberg:// • • •Miketlester
in reply to daniel:// stenberg:// • • •Troed SΓ₯ngberg
in reply to daniel:// stenberg:// • • •dendrite
in reply to daniel:// stenberg:// • • •Even Rouault
in reply to daniel:// stenberg:// • • •Patrick Loftus π
in reply to daniel:// stenberg:// • • •Thomas Svensson π
in reply to daniel:// stenberg:// • • •I just think it is so funny of them to use "gentle reminder" to "request" others to save their bacon for free.
Their internal reasoning and strategizing to come up with that would be interesting to know.
Varx
in reply to Thomas Svensson π • • •@tsvenson This is worded exactly the way Ive seen when dealing with paid software licenses.
They're evidently mixing supported software where they have a paid license and FOSS software into the same risk analysis process which is stupid for obvious reasons.
daniel:// stenberg://
in reply to Varx • • •Thomas Svensson π
in reply to daniel:// stenberg:// • • •@varx
It is likely that the compliance staff is quite clueless when it comes to open source licenses. Plus they are an ocean away from those who chose and implemented the use. Who could select open source as there are no contract and financial transactions involved.
I really hope EU is serious about enforcing this new regulation, so these freeloaders will have to make good to continue using open source.
Julian Andres Klode π³οΈβπ
in reply to daniel:// stenberg:// • • •Today they sent one for APT.
lists.debian.org/deity/2025/08β¦
Oh I see they even have HTML, neither Thunderbird nor Neomutt (duh) rendered that :D
Attached is my reply...
Cybersecurity Risk Assessment Request from Emerson for apt
lists.debian.orgdaniel:// stenberg://
in reply to Julian Andres Klode π³οΈβπ • • •Julian Andres Klode π³οΈβπ
in reply to daniel:// stenberg:// • • •