Recent Posts

OSI calls for revision of disclosure rules in CRA

OSI is a co-signatory of an open letter sent this week to the European Parliament by European Digital Rights (EDRi) expressing concern that the Cyber Resilience Act (CRA) draft currently under consideration still includes mandatory requirements for vulnerability disclosure that violate best practices in Open Source software collaborations and are likely to actually undermine the security of digital products and the individuals who use them.

The Cyber Resilience Act introduces uncertainty and risk leaving Open Source projects confused

What might happen if the uncertainty persists around who is held responsible under the Cyber Resilience Act (CRA)? The global Open Source community is averse to legal risks and generally lacks access to counsel, so it’s very possible offers of source code will simply be withdrawn rather than seeking to resolve the uncertainty.

What Is Open Governance? Drafting a charter for an Open Source project

Building a healthy Open Source community is much more than just choosing an Open Source license for the project. It involves creating a contributing guide, adopting a code of conduct, and establishing an open governance structure that allows all members to actively participate in and contribute to the project. This article provides a hands on guide on how to establish an open governance structure for an Open Source project.