TL;DR The EU is working on the Cyber Resilience Act (CRA) which will be voted on the 19th of July. The current wording makes it look like it will affect open source projects that receice donations; which have contribution from corporate developers; and might break coordinated vulnerability disclousure.
If you live in the EC area, there's a link on the blog to contact to MEP.
The blog also links to other posts from OSS organisations sharing the same concer.
* https://blogs.eclipse.org/post/mike-milinkovich/european-cyb...
* https://pyfound.blogspot.com/2023/04/the-eus-proposed-cra-la...
* https://blog.opensource.org/the-ultimate-list-of-reactions-t...