Cybersecurity Risk Assessment Request
daniel.haxx.se/blog/2025/07/11…
Cybersecurity Risk Assessment Request
With the new EU legislation Cyber Resiliency Act (CRA), there are new responsibilities and requirements put on manufacturers of digital products and services in Europe.daniel.haxx.se
Kushal Das
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Kushal Das • • •zhenech
in reply to daniel:// stenberg:// • • •Seth Larson
in reply to daniel:// stenberg:// • • •Thank you for sharing this! It's likely that we'll be receiving this form soon, too. This helps us "get ahead" and have a template response ready beforehand.
IANAL, but adding a reminder for readers that open source stewards don't have many obligations under the Cyber Resilience Act and maintainers/contributors have zero. This form is likely being sent out to all "suppliers" (in the eyes of the company using the software) regardless of whether they know your obligations or not.
daniel:// stenberg://
in reply to Seth Larson • • •Seth Larson
in reply to daniel:// stenberg:// • • •Maybe? I'm kinda hopeful that we'll go through a period of "learning" where there'll be plenty of unwelcome forms being emailed to maintainers, we'll make a lot of noise, the industry will see that noise, and then people will learn that they are responsible for their open source component security and cold-emailing random people doesn't change that
That seems to be what happened with the SSDF, albeit at a much smaller scale than the CRA (US Gov versus any digital company selling in EU).
Thomas Svensson 🖖
in reply to daniel:// stenberg:// • • •I'd say this is an opportunity for #FOSS maintainers to collaborate taking advantage of. These companies that have been fortunate to earn tons of money by using open software without contributing back, can no longed do that if they want to keep doing business in the EU.
What could be a good EU based FOSS interest group to manage this smartly, collect _fees_ to distribute to maintainer of the used software.
Does @opencollective have an EU presence?
daniel:// stenberg://
in reply to Thomas Svensson 🖖 • • •Thomas Svensson 🖖
in reply to daniel:// stenberg:// • • •That's good, planting a standard.
Especially interesting since it is an old version. Will they need to consult you for every new version they want to update to then?
daniel:// stenberg://
in reply to Thomas Svensson 🖖 • • •Thomas Svensson 🖖
in reply to daniel:// stenberg:// • • •Eckes
in reply to daniel:// stenberg:// • • •Having Said that, it’s probably best to have a static CRA page and SBOMs.
daniel:// stenberg://
in reply to Eckes • • •Eckes
in reply to daniel:// stenberg:// • • •Zimmie
in reply to daniel:// stenberg:// • • •> Are there any vulnerabilities in the latest version which are not disclosed publicly? If yes, when will it be fixed and released? please mention in Remark column.
Probably! The fixes will be released some time after the vulnerabilities are found.
Bradley Kuhn
in reply to daniel:// stenberg:// • • •Thanks for your post & your counter 😆
I'm curious: you characterize the EU #CRA as requiring #SBOM's *specifically*. I know the License Compliance Industrial Complex wants it to be true, but I researched this issue for my #FOSDEM 2025 talk…
fosdem.org/2025/schedule/event…
… & IIUC CRA *doesn't* specify SBOMs specifically.
IMO, if the vendor gives the customer complete, Corresponding Source & a 100% @reproducible_builds they've complied with CRA. No one has shown me anything that disproves that.
FOSDEM 2025 - Is There Really an SBOM Mandate?
fosdem.orgdaniel:// stenberg://
in reply to Bradley Kuhn • • •Bradley Kuhn
in reply to daniel:// stenberg:// • • •Oh, I agree: confused users will request #SBOM's b/c they think they're useful (… even though they aren't).
My point is: we're still at a moment where we can influence actual implementation of CRA in practice (regulations are being written now).
The best approach? Convince regulators that complete, corresponding source &
@reproducible_builds are *actually* useful to customers for FOSS.
#SBOM's are only useful for proprietary software. SBOMs for FOSS is make-work.
Cc: @msw @lexelas
daniel:// stenberg://
in reply to Bradley Kuhn • • •Bradley Kuhn
in reply to daniel:// stenberg:// • • •wrote:
> I think of SBOMs as a way for us to charge
So does the Compliance Industrial Complex. They've been planning for this. 💰's on the table when make-work becomes mandatory regulation.
I doubt small FOSS business'll get a piece of that pie easily. #SBOM game is already rigged to favor Big Tech.
But, I hope I'm wrong & you make a living from it!
Let's reserve the right to “I told you so” each other when one of us turns out wrong in 5-10 years. ☺
Cc: @msw @lexelas
@jeremiah_
daniel:// stenberg://
in reply to Bradley Kuhn • • •Bradley Kuhn
in reply to daniel:// stenberg:// • • •wrote:
> I'm mostly floating along trying to survive and have fun doing it.
I'm admittedly slightly envious. Such comments remind me in my deepest & truest heart, I'd rather be a FOSS developer again than a FOSS policy wonk who is constantly too busy at that to code.
I felt morally obligated to work on policy so FOSS developers could have fun while I did all the horrible work. Then it became a career.
The experience taught me it's possible to be *too* altruistic sometimes.😆
Cc: @msw
Matt "msw" Wilson
in reply to daniel:// stenberg:// • • •I think that the money-value of SBOMs (as an "information good", i.e. a digital artifact that you produce and sell) isn't particularly high.
What people want is an assurance that you are implementing, and promise to perform in the future, secure software development processes that include supply chain risk management tools and methods.
SBOMs might be something that can be produced as a side effect (i.e., "evidence of performance")...
@bkuhn @reproducible_builds @lexelas
Jeremiah C. Foster 🇸🇪🇺🇸🍥
in reply to Bradley Kuhn • • •daniel:// stenberg://
in reply to Jeremiah C. Foster 🇸🇪🇺🇸🍥 • • •Merospit
in reply to daniel:// stenberg:// • • •For the double-quotes, it may be a reused template, and the quotes may look more reasonable for products with spaces in their names.
Completely agree that companies asking for this level of governance should have support contracts.
Colin Watson
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Colin Watson • • •Colin Watson
in reply to daniel:// stenberg:// • • •