curl Cybersecurity Risk Assessment Request
daniel.haxx.se
daniel.haxx.se
There's some good pro-consumer intent in this law, but as is often the case the regulators barely understand the ecosystem they're regulating. It was not designed with the massive importance of open-source in mind from the start.
That's likely the outcome that the corporate interests behind EU CRA want: to put a lasso around the neck of open source and have it be something that either serves them, or does not exist.
https://lwn.net/Articles/944300/ https://lwn.net/Articles/1023306/
What if you're not probably already doing those things?
https://lwn.net/Articles/944300/ https://lwn.net/Articles/1023306/
If it's made simple enough (with an EU legal entity), I see it quite likely.
Feels like classic Big-4 CYA checkbox theater.