ON
← Back to feed
Eclipse and OWASP want to educate open source projects on security issues
Germany💻 TechnologyCenter4 hr. ago

Eclipse and OWASP want to educate open source projects on security issues

The Eclipse Foundation and OWASP have announced a collaboration aimed at enhancing the security of open-source projects and their associated industries, particularly in light of the upcoming EU Cyber Resilience Act (CRA), which will take effect on September 11. The initiative focuses on preparing open-source maintainers, developers, and organizations for regulatory requirements by improving their security practices. Key areas include CRA readiness for the open-source ecosystem, alignment between security frameworks, community education, support for maintainers, and awareness of guidelines. The partnership plans to offer webinars, training sessions, and roundtables focused on topics like software bills of material and supply chain security. While open-source projects are less directly affected by the CRA compared to commercial entities, some regulations still apply. The EU has recently published a guideline to clarify these rules.

The European Commission has released a detailed guidance document aimed at clarifying how the Cyber Resilience Act (CRA) applies to open source software. Published on Monday, the guide provides manufacturers, developers, and companies with a comprehensive overview of how to interpret the cybersecurity regulation, which came into effect in December 2024. The CRA sets uniform minimum security requirements for digital products throughout their entire lifecycle, affecting everything from product design to end-of-life support. The guidance covers key aspects of the CRA, including which products fall under its scope, how major updates should be classified, and how long support periods must last. It also outlines practical steps for conducting risk assessments and fulfilling reporting obligations. The document emphasizes the importance of clarity for small and medium-sized enterprises, offering numerous examples and scenarios to help users understand complex provisions. This is particularly crucial as the first mandatory reporting requirements under the CRA are set to take effect soon. The guidance also addresses concerns raised by open source communities during negotiations over the CRA. Developers and open source foundations had warned that new liability and documentation requirements could discourage volunteer contributions. In response, the Commission clarified that freely available open source software does not fall under the CRA unless it is distributed commercially. The document explains when such commercial activity occurs, noting that selling open source software, providing paid enterprise versions, or monetizing other services through an open source project counts as commercial activity under the CRA. The Commission further distinguishes between contributors and maintainers within open source projects. Those who merely fix bugs or add features generally do not bear responsibility under the CRA. However, individuals or organizations that control the release schedule, manage updates, or oversee the direction of a project, such as project stewards, are subject to different obligations. Simply having write access to a code repository is not enough to qualify as a maintainer under the CRA. The role of “stewards” is also clearly defined. These can include foundations or other entities that provide ongoing organizational or technical support to open source projects without actively promoting them. Their responsibilities vary depending on the level of involvement. For example, those who only handle community work have fewer obligations than those managing infrastructure or actively participating in development and security management. Depending on the nature of their support, stewards may also face reporting requirements related to security incidents or exploited vulnerabilities. In addition, the Commission outlines criteria for determining whether a change to a product qualifies as “essential.” Updates that solely address known vulnerabilities or enhance existing security levels typically do not constitute essential changes. This helps clarify what constitutes a significant update under the CRA, reducing ambiguity for both developers and regulators. The document aims to ensure that open source projects remain viable while still meeting the cybersecurity standards required by the CRA.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Go to the primary sources (3)

The official sources this coverage is built on. Read them directly to bypass framing.

2 reports

heise online logoheise onlineIndependentCenterFactual 95Objective 885 days ago
Cyber Resilience Act: Commission creates more clarity for open source

The European Commission has published a detailed guideline to clarify the implementation of the Cyber Resilience Act (CRA), which came into effect in December 2024. The guide, spanning nearly 80 pages, provides clarity on how the regulation applies to digital products across their entire lifecycle, including definitions of affected products, essential software updates, and rules for open-source software. It addresses industry concerns by explaining how to fulfill risk assessments and mandatory reporting requirements while reducing unnecessary administrative burdens, particularly for startups and small businesses. Special attention is given to open-source projects, clarifying that they generally fall outside the CRA unless distributed commercially. The document outlines scenarios where open-source software might be considered commercial, such as selling enterprise versions or monetizing services through the software.

Bias read (Center): The article presents factual information about the EU Commission’s guidance on implementing the Cyber Resilience Act, focusing on technical and regulatory clarification rather than taking a stance on political issues. There is no evident ideological framing, loaded language, or one-sided sourcing.

Why factuality (95): The article accurately reflects the primary source document by detailing the purpose and content of the guidance published by the European Commission. It mentions the Cyber Resilience Act's implementation timeline, the focus on clarifying product scope, substantial modifications, support periods, an

Why objectivity (88): The article maintains a generally neutral tone, presenting facts about the guidance and its implications for different sectors. However, it slightly emphasizes the importance of the guidance for Open Source developers, which could be seen as a minor editorial tilt toward addressing concerns raised b

heise online logoheise onlineIndependentCenter4 hr. ago
Eclipse and OWASP want to educate open source projects on security issues

The Eclipse Foundation and OWASP have announced a collaboration aimed at enhancing the security of open-source projects and their associated industries, particularly in light of the upcoming EU Cyber Resilience Act (CRA), which will take effect on September 11. The initiative focuses on preparing open-source maintainers, developers, and organizations for regulatory requirements by improving their security practices. Key areas include CRA readiness for the open-source ecosystem, alignment between security frameworks, community education, support for maintainers, and awareness of guidelines. The partnership plans to offer webinars, training sessions, and roundtables focused on topics like software bills of material and supply chain security. While open-source projects are less directly affected by the CRA compared to commercial entities, some regulations still apply. The EU has recently published a guideline to clarify these rules.

Bias read (Center): The article discusses a technical collaboration between two non-profit organizations focused on improving open-source security standards. It provides factual information about the partnership, its goals, and the regulatory context (EU Cyber Resilience Act). There is no evident ideological framing, o

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.

Become a Supporter

Related stories