TechTarget reports from Open Source Summit Europe in Prague that a surge of AI-generated and AI-sourced code is adding unprecedented stress to software supply chains, just as the EU Cyber Resilience Act’s vulnerability-reporting mandates took effect in September and place potentially costly liability on organizations that ship software in Europe. Under the CRA, open source dependencies that were previously treated separately from software products now fall within the liability of the commercial products that use them, and presenters described traditional software bills of materials as a band-aid for gushing wounds. The Open Source Security Foundation’s Launchpad Special Interest Group, co-chaired by Microsoft, is working to create machine-readable CRA due-diligence baselines that span open source components.
AI coding tools strain SBOM controls as EU Cyber Resilience Act shifts open source liability
TechTarget reports from Open Source Summit Europe in Prague that a surge of AI-generated and AI-sourced code is adding unprecedented stress to software supply chains, just as the EU Cyber Resilience Act's vulnerability-reporting mandates took effect in September and place potentially costly liability on organizations that ship software in Europe. Under the CRA, open source dependencies that were previously treated separately from software products now fall within the liability of the commercial products that use them, and presenters described traditional software bills of materials as a band-aid for gushing wounds. The Open Source Security Foundation's Launchpad Special Interest Group, co-chaired by Microsoft, is working to create machine-readable CRA due-diligence baselines that span open source components.
Source: Techtarget