Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [open-regulatory-compliance] Maintainer considering removing project due to CRA obligations and uncertainty

Seth Michael wrote on 2024-12-19:
I'm not sure the PSF or any other foundation like it is in a position to absorb
all projects under, in our example, PyPI. However, we still have our eyes on
lowering the bar, for example I have plans this upcoming year to make complying with the "vulnerability reporting"
and "market surveillance compliance" easier for maintainers. Things like an official
location for a security policy, report a vulnerability, and a process for contacting all relevant market
surveillance groups (CISA, ENISA, etc) in the case of actively exploited vulnerabilities.

Thanks! I suspect people mostly want to outsource having to *think* about these things. To a certain extent that's not possible, but without a massified solution we're likely to end up with useless and counterproductive practices like the cookie banners which do nothing but annoy people (as they don't actually fix the legal basis for whatever you're doing).

PyPI is a massive undertaking so it's hard to think of one-size-fits-all solutions, but it *might* be possible to collect the most salient information from maintainers and automatically generate some suggestions both for the maintainers and the reusers (including the hopefully most common case "you probably don't have to worry").

Best,
	Federico Leva


Back to the top