Review?
Review?
Posted Apr 27, 2026 9:23 UTC (Mon) by tchernobog (subscriber, #73595)In reply to: Review? by pabs
Parent article: Dependency-cooldown discussions warm up
Some kind of way of reliably checking the author of a change, e.g. via proper code signing and on-boarding of developers. But with AI taking more and more the helm, this is getting to be a fuzzy concept anyway. There are some attempts with e.g. https://slsa.dev/
> Have we seen any early effects of the EU CRA on companies yet? Are they talking about internally yet?
I can only speak for my company, a EU mid-sized manufacturer (around 1'000 employees, ~ half a billion yearly revenue).
I can tell that:
* we are well aware of the requirements and are currently (and slowly: we are a hardware company too) working towards compliance
* this led to the creation of internal processes and structures that weren't there to respond requirements; this means also the establishment of an independent security team which was not there before, which is good
* we have now a (not huge, but not tiny) budget to spend on external contractors for fixing important open-source bugs, e.g. in u-boot, hashicorp vault, and more
* we have now full SBoM scanning for all dependencies and are taking timely action to reduce risks around unmaintained or buggy dependencies. So well maintained projects will get more attention, poorly maintained FOSS projects will get the kick
But I cannot speak of course for all companies; this is only anecdotal evidence that something is happening.
