[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
[
List Home]
Re: [open-regulatory-compliance] Maintainer considering removing project due to CRA obligations and uncertainty
|
Seth Michael wrote on 2024-12-19:
I'm not sure the PSF or any other foundation like it is in a position to absorb
all projects under, in our example, PyPI. However, we still have our eyes on
lowering the bar, for example I have plans this upcoming year to make complying with the "vulnerability reporting"
and "market surveillance compliance" easier for maintainers. Things like an official
location for a security policy, report a vulnerability, and a process for contacting all relevant market
surveillance groups (CISA, ENISA, etc) in the case of actively exploited vulnerabilities.
Thanks! I suspect people mostly want to outsource having to *think*
about these things. To a certain extent that's not possible, but without
a massified solution we're likely to end up with useless and
counterproductive practices like the cookie banners which do nothing but
annoy people (as they don't actually fix the legal basis for whatever
you're doing).
PyPI is a massive undertaking so it's hard to think of one-size-fits-all
solutions, but it *might* be possible to collect the most salient
information from maintainers and automatically generate some suggestions
both for the maintainers and the reusers (including the hopefully most
common case "you probably don't have to worry").
Best,
Federico Leva