# Securing Open Source Software Act of 2022

**URL:** https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098
**Category:** 📣 Sustainer Talk
**Created:** [October 3, 2022, 6:25pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098 "2022-10-03T18:25:08Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![epicfaace](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/epicfaace/32/649_2.png) [@epicfaace](https://discourse.sustainoss.org/u/epicfaace)
#### Post date: [October 3, 2022, 6:25pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/1 "2022-10-03T18:25:08Z")

</div>

This bill was just introduced last week – what do you all think?

> **[Majority Media |

	Homeland Security & Governmental Affairs Committee...](https://www.hsgac.senate.gov/media/majority-media/peters-and-portman-introduce-bipartisan-legislation-to-help-secure-open-source-software_)**

> **[Text - S.4913 - 117th Congress (2021-2022): Securing Open Source Software Act...](https://www.congress.gov/bill/117th-congress/senate-bill/4913/text)**
>
> Text for S.4913 - 117th Congress (2021-2022): Securing Open Source Software Act of 2022

> **[Senate Legislation to Secure Open Source Software Relies on Transparency...](https://www.nextgov.com/cybersecurity/2022/09/senate-legislation-secure-open-source-software-relies-transparency-initiative/377722/)**
>
> Success would depend to a significant degree on whether agencies require vendors of information and communications technology to provide a software bill of materials with their products and services.

> **[The United States Securing Open Source Software Act: What You Need to...](https://openssf.org/blog/2022/09/27/the-united-states-securing-open-source-software-act-what-you-need-to-know/)**
>
> The Securing Open Source Software Act is in response to the Log4Shell vulnerability discovered in late November 2021. What is the Securing Open Source Software Act about? On 21st September 2022, U.S. Senators Gary Peters (D-MI) and Rob Portman...

---

<div class="post-metadata">

### Author: ![LawrenceHecht](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/lawrencehecht/32/271_2.png) [@LawrenceHecht](https://discourse.sustainoss.org/u/LawrenceHecht)
#### Post date: [October 3, 2022, 7:01pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/2 "2022-10-03T19:01:15Z")

</div>

There is a lot of very specific language used in the bill. It’s as if they copied material that was submitted to them from earlier hearings. Or from what was given to them from a lobbyist.

---

<div class="post-metadata">

### Author: ![LawrenceHecht](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/lawrencehecht/32/271_2.png) [@LawrenceHecht](https://discourse.sustainoss.org/u/LawrenceHecht)
#### Post date: [October 3, 2022, 7:03pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/3 "2022-10-03T19:03:29Z")

</div>

If someone can get Senator Peters to speak about this bill when CloudNativeCon is in Detroit, that would be a coup.

---

<div class="post-metadata">

### Author: ![RichardLitt](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/richardlitt/32/8_2.png) [@RichardLitt](https://discourse.sustainoss.org/u/RichardLitt)
#### Post date: [October 4, 2022, 3:21pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/4 "2022-10-04T15:21:08Z")

</div>

Thank you, @epicfaace, for posting these! Great coverage of the issue.

@LawrenceHecht, I don’t understand what you’re trying to say in your comments. Of course this is iterative work, and, yes, there are people lobbying on behalf of this bill.

In general: My main questions are - what provisions are there for helping open source projects make SBOMs. I’m not sure they even make sense from a dependency point of view, and they add a ton of work for maintainers. It sounds to me like this is asking for yet more work from OSS maintainers, not less.

I also think that some federal agencies have almost certainly already made studies of the security of their OSS dependencies. Curious to see how those will be worked in on public record.

Cool stuff. Good to see Trey quoted in particular - he’s been doing great work.

---

<div class="post-metadata">

### Author: ![LawrenceHecht](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/lawrencehecht/32/271_2.png) [@LawrenceHecht](https://discourse.sustainoss.org/u/LawrenceHecht)
#### Post date: [October 4, 2022, 4:43pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/5 "2022-10-04T16:43:40Z")

</div>

> [@RichardLitt](#):
>
> In general: My main questions are - what provisions are there for helping open source projects make SBOMs. I’m not sure they even make sense from a dependency point of view, and they add a ton of work for maintainers. It sounds to me like this is asking for yet more work from OSS maintainers, not less.

I was being reactionary. I mostly want to know who is lobbying for the bill.

I’m also interested in who will co-sponsor the bill next session. I’m assuming this won’t get appended to an omnibus package and will have to be re-introduced next year.

---

<div class="post-metadata">

### Author: ![coni2k](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/coni2k/32/1336_2.png) [@coni2k](https://discourse.sustainoss.org/u/coni2k)
#### Post date: [October 9, 2022, 6:43pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/6 "2022-10-09T18:43:38Z")

</div>

These are crucial initiatives; thanks for sharing the links!

I’m curious; did PlainText have any connections with this bill since there was already an [OSPO proposal](https://github.com/PlaintextGroup/oss-virtual-incubator/blob/46355eb6626ad2f267cb7b73deee556c6345ce43/proposals/center-for-open-source-security.md) under the incubator program?

* * *

Here are some questions/feedback:

As mentioned in the last “Sustain Together” meeting, the bill doesn’t refer to OSI regarding [open-source software definition](https://www.congress.gov/bill/117th-congress/senate-bill/4913/text#id319902784BD14DC38AB462E270F1726A). Is there any specific reason for this, like it’s better to stay generic? And is this a trivial detail?

About the [Open Source Risk Assessment Framework](https://www.congress.gov/bill/117th-congress/senate-bill/4913/text#id2E6B3340D2094A61B77A7380FFAB5D39), they plan to make the software/algorithm open source and share the results/datasets publicly. Making the entire process open/public would be essential; the community should review which software is/becomes critical under which conditions.

Last, the bill’s primary focus is security again, which can be an easy sell and a good start.

However, these conversations will become more exciting once we acknowledge the economic value of the open-source ecosystem and start addressing our systemic failure of collective investment (giving back the fair share of the value that the ecosystem generated in the economy).

If/once there are national OSPOs, the OSS community could/should use these opportunities and proactively help them expand in such directions.

---

<div class="post-metadata">

### Author: ![downey](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/downey/32/1243_2.png) [@downey](https://discourse.sustainoss.org/u/downey)
#### Post date: [October 9, 2022, 7:35pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/7 "2022-10-09T19:35:45Z")

</div>

Some additional coverage here:

> **[New Cyber Bill Aims To Fix Open-Source Security in Government](https://www.linuxinsider.com/story/new-cyber-bill-aims-to-fix-open-source-security-in-government-176676.html)**
>
> Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, introduced the legislation that seeks to address open source software risks in government. The proposed Bill, S. 4913, now awaits action by the Committee on Homeland Security and Governmental...

I agree it is concerning that the authors don’t seem to be making themselves known. I have my hunches…

---

<div class="post-metadata">

### Author: ![bzg](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/bzg/32/59_2.png) [@bzg](https://discourse.sustainoss.org/u/bzg)
#### Post date: [October 12, 2022, 5:14am UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/8 "2022-10-12T05:14:59Z")

</div>

> As mentioned in the last “Sustain Together” meeting, the bill doesn’t refer to OSI regarding open-source software definition. Is there any specific reason for this, like it’s better to stay generic? And is this a trivial detail?

I believe this is _not_ a trivial detail.

Working for the OSPO of the French gov, I confirm it is critical to have a definition of FLOSS based on a list of licences.

We explicitely have a consensual and restricted one: (1) FLOSS-for-fr-gov encompasses software published under a license that is approved by _both_ the FSF and the OSI, as per [SPDX License List | Software Package Data Exchange (SPDX)](https://spdx.org/licenses/) and (2) we allow ourselves to decide whether a variant of a license within this list is FLOSS or not.

---

<div class="post-metadata">

### Author: ![abitrolly](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/abitrolly/32/845_2.png) [@abitrolly](https://discourse.sustainoss.org/u/abitrolly)
#### Post date: [October 12, 2022, 6:31am UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/9 "2022-10-12T06:31:30Z")

</div>

I can not read legalize, so I haven’t read the the text. Two things are concerning me:

1. Preserve the ability to release the code out of copyright limitations (e.g. `public domain`). If I remember correctly, the code that is developed by government agencies using public money should be put into public domain, so that everybody could have equal right reusing this code. I believe that’s how OpenStack became possible. Just to remind - SPDX erases the notion of public domain, replacing it with license.

2. It is so easy to attack individual developers as “insecure” sources of software, by disregarding public review practices and multistage release process, meaning that the Act could do worse by forcing companies to use only OSS from trusted vendors. This will replace Open Source with open core, erase the community, will place restrictions on funding. And as a result we will get less diverse and awesome projects. Not speaking about code that is written by pseudonymous people to avoid them being hired by somebody else, or whatever. Open Source should not only mean “code”, but also preserver developers freedoms to be known, and to communicate freely.

---

<div class="post-metadata">

### Author: ![coni2k](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/coni2k/32/1336_2.png) [@coni2k](https://discourse.sustainoss.org/u/coni2k)
#### Post date: [November 12, 2022, 5:18pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/10 "2022-11-12T17:18:59Z")

</div>

I came across the cost estimate for this bill 👇

> CBO estimates that implementing the bill would cost $275 million over the 2023-2027 period.

> **[s4913.pdf](https://www.cbo.gov/system/files/2022-11/s4913.pdf)**
>
> 247.05 KB

* * *

And here are the remarks from [Dustin Ingram](https://twitter.com/di_codes), one of the board members of PSF:

> <https://twitter.com/di_codes/status/1590746681695272966>

> <https://twitter.com/di_codes/status/1574447938054410246>

---

<div class="post-metadata">

### Author: ![jdorfman](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/jdorfman/32/14_2.png) [@jdorfman](https://discourse.sustainoss.org/u/jdorfman)
#### Post date: [November 13, 2022, 5:48pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/11 "2022-11-13T17:48:31Z")

</div>

Thanks for sharing @coni2k, I missed the tweets.

---

<div class="post-metadata">

### Author: ![nebairevelations](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/nebairevelations/32/715_2.png) [@nebairevelations](https://discourse.sustainoss.org/u/nebairevelations)
#### Post date: [November 25, 2022, 1:32am UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/12 "2022-11-25T01:32:24Z")

</div>

These government Bills aren’t about helping OSS financially. But they’re about how to impose more restrictions on this industry. F.E. the EU version of the OSS is looking for pursuing OSS developers with criminal charges.

> **[Open-source software vs. the proposed Cyber Resilience Act](https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-resilience-act/)**
>
> By Maarten Aertsen
> 
> NLnet Labs is closely following a legislative proposal by the European Commission affecting almost all hardware and software on the European market. The Cyber Resilience Act (CRA) intends to ensure cybersecurity of products with...

In a similar way, the EU act for AI would be disastruous for OSS projects and computer science researchers. It’s about how to preserve monopolies in favor of BigTech corporations

> " Under the EU’s draft AI Act, open source developers would have to adhere to guidelines for risk management, data governance, technical documentation and transparency, as well as standards of accuracy and cybersecurity."

> **[The EU's AI Act could have a chilling effect on open source efforts, experts...](https://techcrunch.com/2022/09/06/the-eus-ai-act-could-have-a-chilling-effect-on-open-source-efforts-experts-warn/)**
>
> As written, the European Union's AI Act, which seeks to regulate certain types of AI systems, could impose onerous requirements on open source developers, some experts believe.

---

<div class="post-metadata">

### Author: ![coni2k](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/coni2k/32/1336_2.png) [@coni2k](https://discourse.sustainoss.org/u/coni2k)
#### Post date: [November 27, 2022, 8:28pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/13 "2022-11-27T20:28:43Z")

</div>

Thanks for sharing these articles, @nebairevelations!

About the Cyber Resilience Act, here are my quick takes:

The proposal aims to address the growing number of cyberattacks which are getting increasingly costly:

> “Hardware and software products are increasingly subject to successful cyberattacks, leading to an estimated global annual cost of cybercrime of €5.5 trillion by 2021.”

Here are the four objectives of the proposal:

> 1. Ensure that manufacturers improve the security of products with digital elements since the design and development phase and throughout the whole life cycle;
> 2. Ensure a coherent cybersecurity framework, facilitating compliance for hardware and software producers;
> 3. Enhance the transparency of security properties of products with digital elements, and
> 4. Enable businesses and consumers to use products with digital elements securely.

According to the fact sheet, 90% of the products will fall under the “Default” category (as @osioke pointed out in [the other thread](https://discourse.sustainoss.org/t/excessive-regulations-could-be-a-threat-to-the-oss-industry/1130/2)).

 ![image](https://canada1.discourse-cdn.com/flex032/uploads/sustainoss/original/1X/32c0a5e9dc5b1ce592c5cb499c5bbbefa84b8a8b.png)

And there is a specific exception for non-commercial open source software (Page 16 - Recital 10):

> “In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation.”

Ensuring we have standard security processes/frameworks throughout the industry would help address the growing cyber threats. So, overall, I see it as a “well-intentioned” initiative.

About adding a burden on the OS initiatives, first of all, it would be great to have a good list of commercial OS initiatives that can fall under the critical category (requires auditing). According to their article, NLnet is one of them, but it may not be a long list.

On the other hand, the proposal is currently open for feedback. Shouldn’t we use this as an opportunity?

Ask the EU to set up a dedicated budget for the (commercial or non-commercial) critical OS initiatives (especially from the EU) to cover the arising auditing expenses from this regulation. Then, we can ensure that the OS solutions are still up to the same security standards while not adding any financial burden.

So, I suggest listing our concerns and improvements and sharing them as our feedback, maybe as the Sustain group? We can organize a meeting to discuss this proposal if you wish.

* * *

Here are all the links I found as a quick reference:

- [Cyber Resilience Act | Shaping Europe’s digital future](https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act)
- [Cyber Resilience Act - Factsheet | Shaping Europe’s digital future](https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act-factsheet)
- [Cyber Resilience Act - Feedback](https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/13410-Cyber-resilience-act-new-cybersecurity-rules-for-digital-products-and-ancillary-services_en)
- [Open-source software vs. the proposed Cyber Resilience Act](https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-resilience-act/)
- [The EU's Proposed Cyber Resilience Act Will Damage the Open Source Ecosystem - Internet Society](https://www.internetsociety.org/blog/2022/10/the-eus-proposed-cyber-resilience-act-will-damage-the-open-source-ecosystem/)
- [An Overview of the EU’s Cyber Resilience Act – Center for Data Innovation](https://datainnovation.org/2022/09/an-overview-of-the-eus-cyber-resilience-act/)
- [Cybersecurity Resilience Act - EU proposes stricter cybersecurity rules for connected products - Lexology](https://www.lexology.com/library/detail.aspx?g=8307df51-bab1-4936-8c26-3ac9b5e99afd)
- [Kir Nuthi, “Feedback to the European Commission on the Cyber Resilience Act Initiative”](https://www2.datainnovation.org/2022-cyber-resilience-act-roadmap.pdf)

---

<div class="post-metadata">

### Author: ![vrisk](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/vrisk/32/354_2.png) [@vrisk](https://discourse.sustainoss.org/u/vrisk)
#### Post date: [November 28, 2022, 4:50pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/14 "2022-11-28T16:50:40Z")

</div>

At ISC, we are working with NLNET Labs (Maarten Aertsen, the author of the blog linked above) to try to gather together impacted projects (critical, sustained with ‘commercial services’) to see if we can coordinate our comments on the CRA. We haven’t decided yet what sort of relief we might look for, but possibly an exception for small businesses, or non-profit organizations. I haven’t catalogued all the requirements of the CRA, but the requirement that concerns me the most is the requirement to hire an external auditor. For a small organization even engaging with an auditor is going to be onerous, let alone paying them.

---

<div class="post-metadata">

### Author: ![abitrolly](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/abitrolly/32/845_2.png) [@abitrolly](https://discourse.sustainoss.org/u/abitrolly)
#### Post date: [November 28, 2022, 6:04pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/15 "2022-11-28T18:04:20Z")

</div>

“given enough eyeballs, all [bugs](https://en.wikipedia.org/wiki/Software_bug) are shallow” (c) [Linus's law - Wikipedia](https://en.wikipedia.org/wiki/Linus%27s_law)

“[if all you have is a hammer, everything looks like a nail](https://en.wiktionary.org/wiki/if_all_you_have_is_a_hammer,_everything_looks_like_a_nail)” (c) [Law of the instrument - Wikipedia](https://en.wikipedia.org/wiki/Law_of_the_instrument)

I assume lawyers and legislators practicing the latter while being unaware of the former. The cause of security problems is that Open Source people are losing grounds to review each other’s code. Outsourcing management practices alone perfected selling people time too well to squeeze every hour and ensure they won’t have anything left to work in public. Add here non-compete, NDA, and other papers. People don’t have much time anymore. They can’t enjoy (I can’t enjoy) working on my things when I know that my basic needs are no closed.

How can legislation reduce the stress, the dependency, get more money to OSS folks? In my opinion it can not. At least I don’t see any generic solution written on paper that can not be hacked by guys who are hunting for money. It can only be done by open, transparent support network.

---

<div class="post-metadata">

### Author: ![nebairevelations](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/nebairevelations/32/715_2.png) [@nebairevelations](https://discourse.sustainoss.org/u/nebairevelations)
#### Post date: [November 28, 2022, 6:08pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/16 "2022-11-28T18:08:42Z")

</div>

Do we really need government oversight on programmers activity ? Remember the inventor of the PGP algorithm, (that one that you’re using in your email application and powered internet protocols) ? Zimmermann was prosecuted by the U.S. government because military agencies felt threatened about commoners obtaining the same cybernetic superpowers as them?

Remember, that Free Open Source Software movement is all about FREEDOM!!

> **[When Encryption Was a Crime: The 1990s Battle for Free Speech in Software](https://reason.com/video/2020/10/21/cryptowars-gilmore-zimmermann-cryptography/)**
>
> This is the third installment in Reason's four-part documentary series titled "Cypherpunks Write Code." Watch the complete series here. In...

---

<div class="post-metadata">

### Author: ![dachary](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/dachary/32/665_2.png) [@dachary](https://discourse.sustainoss.org/u/dachary)
#### Post date: [November 28, 2022, 6:25pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/17 "2022-11-28T18:25:19Z")

</div>

> [@abitrolly](#):
>
> The cause of security problems is that Open Source people are losing grounds to review each other’s code.

This is a bold assertion. Could you please provide [secondary sources](https://en.wikipedia.org/wiki/Secondary_source) about it?

---

<div class="post-metadata">

### Author: ![abitrolly](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/abitrolly/32/845_2.png) [@abitrolly](https://discourse.sustainoss.org/u/abitrolly)
#### Post date: [November 28, 2022, 7:30pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/18 "2022-11-28T19:30:19Z")

</div>

That’s just obvious for anybody in the scene. Take a look at how many people maintained OpenSSL before HeartBleed. [https://www.wallarm.com/what/what-is-the-heartbleed-vulnerability](https://www.wallarm.com/what/what-is-the-heartbleed-vulnerability) Or what GraphicsMagick maintainer says in the latest [News](http://www.graphicsmagick.org/NEWS.html#id1):

> GraphicsMagick really does need some additional productive volunteers. For several years now, the burden has entirely been on me (Bob Friesenhahn). I have been sheparding the project for 20 years already (and contributed to ImageMagick and GraphicsMagick combined for 26 years already). It is not reasonable to expect someone with a full time job (and expecting to retire in a few years) to do all of the work.

I personally filled a story with critical flaw in Python’s `zipfile` library that prevents one of the top voted feature for Python Package Index to be implemented. And there are no people to even say if I am right or wrong [Zip Bomb protection for wheels · Issue #10504 · pypi/warehouse · GitHub](https://github.com/pypi/warehouse/issues/10504) No responses from security teams either. What all these people are doing if they have the time?

---

<div class="post-metadata">

### Author: ![coni2k](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.sustainoss.org/coni2k/32/1336_2.png) [@coni2k](https://discourse.sustainoss.org/u/coni2k)
#### Post date: [November 30, 2022, 9:53pm UTC](https://discourse.sustainoss.org/t/securing-open-source-software-act-of-2022/1098/19 "2022-11-30T21:53:25Z")

</div>

> [@vrisk](#):
>
> At ISC, we are working with NLNET Labs (Maarten Aertsen, the author of the blog linked above) to try to gather together impacted projects (critical, sustained with ‘commercial services’) to see if we can coordinate our comments on the CRA.

Sounds great; I’d love to see that list, and I’d be happy to help if there’s anything I can do.

> [@nebairevelations](#):
>
> [When Encryption Was a Crime: The 1990s Battle for Free Speech in Software](https://reason.com/video/2020/10/21/cryptowars-gilmore-zimmermann-cryptography/)

Loved the article/video and will watch the rest! 💯

> [@nebairevelations](#):
>
> Do we really need government oversight on programmers activity ?

I understand the distrust, but that’s quite a stretch. There is a valid issue here, and the proposal aims to address it. There might be side effects to the open source ecosystem, but let’s focus on improving it and sharing our feedback.

I will join this week’s [Sustain call](https://docs.google.com/document/d/1b4dYI8MZiGSCnsXaqxvrM0mtdKmhj4DnuHxjs3kByig/edit#). If it’s okay for everyone, we can discuss this proposal again.

Plus, OpenForum Europe is also organizing a special meeting for this proposal next week on the 6th:

> Next week, 6 December, we are hosting an extra long OFE Community Call focusing on the [Cyber Resilience Act](https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-european-cyber-resilience-act) (CRA) (17:00-18:00 CET).
> 
> We have invited a number of representatives from organisations working on the CRA who will share their thoughts on the proposed law. The particular focus is Recital 10 attempting to exclude certain modes of OSS from the scope of the law.
> 
> - 17:00-17:30: Invited speakers share their views
> - 17:30-18:00: Open discussions on CRA implications and paths forward

[https://groups.google.com/a/openforumeurope.org/g/foss-community/c/55XRB97aaiY](https://groups.google.com/a/openforumeurope.org/g/foss-community/c/55XRB97aaiY)
