Maintainers read the
Cyber Resilience Act (CRA)

Tuesdays, July-Sep, 15:00UTC, Zoom/Github

For too long, governments have engaged with "the open source community" through large companies and foundations- which represent, at best, a shallow, incomplete perspective of the greater open source community, a majority of which is composed of independent maintainers and small business owners.

Join us for a series where we dive deep into the latest critical legislation from the EU with the goal of collecting and documenting maintainer feedback.

Register for the event Check out the Feedback repo

Panel Guests

Every week, Ashley and Tracy will be joined by a set of prolific open source maintainers who will share their raw reactions, opinions, and feedback as we dig through the implications of this new legislation.

Interested in being a panelist? Get in touch!

Ashley Avatar

Ashley Williams

Founder axodotdev, maintainers of cargo-dist; Former Rust Core

mcollina Avatar

Matteo Collina

Co-Founder & CTO Platformatic; maintainer of Fastify; Node.js TSC

charlie Avatar

Charlie Marsh

Founder & CEO Astral, maintainers of ruff and uv

William Avatar

William Morgan

CEO Buoyant, maintainers of linkerd

charlie Avatar

Luis Villa

Co-Founder & General Tidelift

charlie Avatar

Jordan Harband

Principal HeroDevs; maintainer of nvm, qs and many more

What?

The Cyber Resilience Act (CRA) is an EU regulation proposed in 2022 by the for improving cybersecurity and cyber resilience through common cybersecurity standards, for products with hardware and software whose intended and foreseeable use includes a data connection to a device or network.

Do you love reading obscure legislative text about upcoming tech policies that may affect your open source work? Find your people here with this new online series focused on doing a deep-dive read through of the CRA paired with a casual panel-style discussion between open source builders and mainatiners. We'll be collecting feedback and questions on a Github repo for packaging and presentation at the Eclipse Foundation's Regulatory Compliance WG.

We have about 2 years to get ahead of the requirements. We’d love to talk through the annoyances that projects could feel, possible work being asked for by companies that are consumers of your projects, and we are most excited about the potential opportunity for the projects to make the money instead of third party vendors around the upcoming “obligations”.

Register now