Linux Format

Newsdesk

SECURITY

EU passes Cyber Resilience Act

EU states have agreed to draft legislation, despite opposition from the Linux Foundation and others. Is this the end of open source in Europe?

The Cyber Resilience Act was proposed in September 2022 and mostly seems to target interconnected equipment such as IoT devices. In theory, it ensures minimum standards for connected devices as well as requiring mandatory security updates. As well meaning as the legislation is, the impact on open source development could be devastating. In April, more than a dozen open source industry bodies, including the Linux Foundation Europe, wrote an open letter to EU legislators asking them to reconsider the current wording (https://newsroom.eclipse.org/ news/announcements/open-letter-europeancommission-cyber-resilience-act).

In theory, the Act exempts “free and open source software developed or supplied outside the course of a commercial activity”.

In practice, many open source projects would be considered commercial if any contributors were paid for their work. This would encompass most major versions of Linux, as well as popular open source apps such as LibreOffice.

Some aspects of the Act would also be almost impossible to guarantee. In January, GitHub pointed out that Annex I, for instance, would require software to be delivered “without any known exploitable vulnerabilities”. The company points out that vulnerabilities exist on a “continuum of risk” and new ones are being discovered all the time.

The open letter

You’re reading a preview, subscribe to read more.

More from Linux Format

Linux Format2 min read
OBS Studio
Version: 30.0.2 Web: https://obsproject.com There are lots of good options for recording screencasts, but if you want to live-stream T your desktop, one of the best options is OBS Studio. The app works with all the major online streaming providers, s
Linux Format1 min read
Wine For Wayland
2023 was a great year for the Wayland driver for Wine. The goal was to move forward from the experimental phase and make the driver a proper upstream component. A year later, after several merge requests, many people are now already able to use the l
Linux Format2 min read
Back Issues Missed One?
ISSUE 313 April 2024 Product code: LXFDB0313 In the magazine Discover how to use the ultimate hacker’s toolkit, staying out of trouble while doing so. And join us as we take the Puppy Linux developer’s new distro for a run and explore its container

Related