> And what makes matters worse is that the type of open source organizations most affected are also exactly those that, today, tend to have very mature security processes, with vulnerabilities getting triaged, fixed, and disclosed responsibly with CVEs to match. While it generally is further downstream; with the companies that place the product on the market — that the CRA needs to drive significant improvement. It now risks doing the reverse.
But all organizations (ECLIPSE, LINUX, ...) raised alarms
https://news.apache.org/foundation/entry/save-open-source-th...
Edit: https://nitter.kavin.rocks/search?f=tweets&q=cyber+Resilienc...