sigmoid.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A social space for people researching, working with, or just interested in AI!

Server stats:

592
active users

#cyberresilienceact

0 posts0 participants0 posts today

👋 Last call to register for our webinar on "The security project for QGIS" this Thursday 19th at 5 PM (Paris time) !

🔗 framaforms.org/webinar-securit

👉 If you are in the #Geospatial domain, and care about #cybersecurity, do not hesitate to attend to know more !

🔍 You can also check the official project website : security.qgis.oslandia.com

framaforms.orgWebinar Security Project for QGIS | Framaforms.org

Really glad to see the #OSI's efforts highlighted here.

I worked as a Parliament staffer during negotiations on the #CyberResilienceAct, and can say with confidence that if it weren't for OSI, it's educational work, and its efforts to connect lawmakers with Open Source developers, the CRA would have been extremely harmful for the #OpenSource community.

lwn.net/SubscriberLink/1023306

LWN.netOpen source and the Cyber Resilience Act The European Union's Cyber Resilience Act (CRA) has caused a stir in the software-development [...]

To implement best practices and strong guidelines, and also to be compliant with CRA and NIS2, it is more and more mandatory to have an SBOM for its software project.

So, freshly integrated open source tools which can generate an SBOM file in different formats (like CycloneDX or SPDX), and process this file to check if there are know vulnerabilities.

Syft: github.com/anchore/syft

Grype: github.com/anchore/grype

🇪🇺 The EU's Cyber Resilience Act (#CRA) is different from previous compliance requirements. For the first time, full supply chain compliance will be required for all products with digital elements sold in the European market.

💡 If you manufacture, maintain, or steward #opensource software and are unclear about how the CRA might impact you, check out the #ORCWG's GitHub for discussions! github.com/orcwg/cra-hub

GitHubGitHub - orcwg/cra-hub: Everything you ever wanted to know about the CRA and its implementationEverything you ever wanted to know about the CRA and its implementation - orcwg/cra-hub

Conf de @mrybczyn sur le Cyber Resilience Act.

La liste des produits concernés et leurs classes : eur-lex.europa.eu/legal-conten

Le guide du CNLL : linuxfr.org/news/guide-cnll-in

(dans les slides, page 10 il y a un schéma qui explique dans quels cas un produit open source est concerné)

Blog post: 'Cyber Resilience Act (CRA): What You Need to Know' 🔐

The EU's Cyber Resilience Act is reshaping how we think about software security, with significant implications for anyone building or maintaining digital products in the EU.

In our latest blog post, we unpack what the CRA means, when it will be implemented, who it impacts, and outline the penalties for non-compliance.

→ See how the CRA impacts you: codethink.co.uk/articles/what-

www.codethink.co.ukCyber Resilience Act (CRA): What You Need to KnowExplore the EU Cyber Resilience Act (CRA), its impact on businesses and affected sectors, its implementation, and penalties for non-compliance.