Published September 8, 2026 · Added September 9, 2026

The EU CRA's Real Question: What Shipped, and When Did You Know?

BleepingComputer publishes ActiveState's analysis of the EU Cyber Resilience Act reporting deadline, using an open-source maintainer's vulnerability-disclosure ordeal to argue that software vendors need fresh SBOMs, provenance, and evidence of what shipped and when vulnerabilities became known.

BleepingComputer publishes ActiveState’s analysis of the EU Cyber Resilience Act reporting deadline, using an open-source maintainer’s vulnerability-disclosure ordeal to argue that software vendors need fresh SBOMs, provenance, and evidence of what shipped and when vulnerabilities became known.

Read the original story.

Source: Bleepingcomputer