Skip to content

How do the CRA reporting obligations for open source software stewards apply to vulnerabilities in obsolete versions? #354

Description

@mbarbero

I have not found clear guidance on whether an open source software steward’s reporting obligations are limited by anything comparable to a product’s “support period.”

Suppose a steward becomes aware of an actively exploited vulnerability affecting version 2.1.0 of an open source project, released in 2008. The project itself remains actively maintained, and the current release is version 9.4.3, but version 2.1.0 has not been maintained or supported for many years.

Would the steward still have an obligation under the Cyber Resilience Act to report the actively exploited vulnerability?

Section 9.1, paragraph 211 of the latest guidance states that, for manufacturers, reporting obligations continue even after a product is no longer supported:

Unlike the obligation to comply with vulnerability handling obligations, which continues for the duration of the product’s support period, reporting obligations continue to apply also after a product is no longer supported.

However, this passage appears to address manufacturers rather than open source software stewards.

More broadly, how should a steward determine which historical versions remain within the scope of its reporting obligations? For example, version 2.1.0 from 2008 is clearly no longer maintained, but an earlier release such as version 9.3.1, issued five months ago, may also no longer receive updates once superseded.

Where does the CRA draw the line between versions for which a steward must report an actively exploited vulnerability and versions that are sufficiently obsolete to fall outside the reporting obligation?

Are stewards expected to report actively exploited vulnerabilities on the same basis as manufacturers—meaning that the reporting obligation continues indefinitely, including for versions that have been unsupported for many years?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions