I have not found clear guidance on whether an open source software steward’s reporting obligations are limited by anything comparable to a product’s “support period.”
Suppose a steward becomes aware of an actively exploited vulnerability affecting version 2.1.0 of an open source project, released in 2008. The project itself remains actively maintained, and the current release is version 9.4.3, but version 2.1.0 has not been maintained or supported for many years.
Would the steward still have an obligation under the Cyber Resilience Act to report the actively exploited vulnerability?
Section 9.1, paragraph 211 of the latest guidance states that, for manufacturers, reporting obligations continue even after a product is no longer supported:
Unlike the obligation to comply with vulnerability handling obligations, which continues for the duration of the product’s support period, reporting obligations continue to apply also after a product is no longer supported.
However, this passage appears to address manufacturers rather than open source software stewards.
More broadly, how should a steward determine which historical versions remain within the scope of its reporting obligations? For example, version 2.1.0 from 2008 is clearly no longer maintained, but an earlier release such as version 9.3.1, issued five months ago, may also no longer receive updates once superseded.
Where does the CRA draw the line between versions for which a steward must report an actively exploited vulnerability and versions that are sufficiently obsolete to fall outside the reporting obligation?
Are stewards expected to report actively exploited vulnerabilities on the same basis as manufacturers—meaning that the reporting obligation continues indefinitely, including for versions that have been unsupported for many years?
I have not found clear guidance on whether an open source software steward’s reporting obligations are limited by anything comparable to a product’s “support period.”
Suppose a steward becomes aware of an actively exploited vulnerability affecting version 2.1.0 of an open source project, released in 2008. The project itself remains actively maintained, and the current release is version 9.4.3, but version 2.1.0 has not been maintained or supported for many years.
Would the steward still have an obligation under the Cyber Resilience Act to report the actively exploited vulnerability?
Section 9.1, paragraph 211 of the latest guidance states that, for manufacturers, reporting obligations continue even after a product is no longer supported:
However, this passage appears to address manufacturers rather than open source software stewards.
More broadly, how should a steward determine which historical versions remain within the scope of its reporting obligations? For example, version 2.1.0 from 2008 is clearly no longer maintained, but an earlier release such as version 9.3.1, issued five months ago, may also no longer receive updates once superseded.
Where does the CRA draw the line between versions for which a steward must report an actively exploited vulnerability and versions that are sufficiently obsolete to fall outside the reporting obligation?
Are stewards expected to report actively exploited vulnerabilities on the same basis as manufacturers—meaning that the reporting obligation continues indefinitely, including for versions that have been unsupported for many years?