BleepingComputer publishes ActiveState’s analysis of the EU Cyber Resilience Act reporting deadline, using an open-source maintainer’s vulnerability-disclosure ordeal to argue that software vendors need fresh SBOMs, provenance, and evidence of what shipped and when vulnerabilities became known.
The EU CRA's Real Question: What Shipped, and When Did You Know?
BleepingComputer publishes ActiveState's analysis of the EU Cyber Resilience Act reporting deadline, using an open-source maintainer's vulnerability-disclosure ordeal to argue that software vendors need fresh SBOMs, provenance, and evidence of what shipped and when vulnerabilities became known.
Source: Bleepingcomputer