home.social

#cramondays — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cramondays, aggregated by home.social.

fetched live
  1. This team analysed over 350 organisations and 3,600 repositories within projects to learn whether their compliance solution could be applied to a large organisation.

    Tune in to our latest edition of to hear Martin von Willebrand (Double Open) and Sebastien Heurtematte (Eclipse Foundation) present the latest results from OCCTET.

    📺 Watch the full session on our new YouTube channel: youtu.be/KN3dKD38S9U?si=OXtwkA

  2. This might be the solution to automating compliance at scale. ⚙️

    This session, presented by Martin von Willebrand (Double Open) and Sebastien Heurtematte (@EclipseFdn) features key findings from an analysis of projects across technology ecosystems and compares ORT Server results with GitHub advisory data, highlighting differences in coverage and vulnerability detection.

    📺 Watch the full session on YouTube: youtu.be/KN3dKD38S9U?si=OXtwkA

  3. What did Log4Shell teach us about securing open source?

    Join the ORC WG on Monday to explore the lessons from Log4Shell and what a CRA-ready Log4j looks like.

    📆 March 16 at 12 pm EDT
    ➕ Add to your calendar: buff.ly/GZ8m6Gv

  4. Log4Shell revealed just how deeply open source runs through the global software supply chain—and how hard it can be to respond when a critical dependency fails.

    Join the ORC WG for the next to explore the lessons from Log4Shell and what it takes to build a CRA-ready Log4j.

    📆 March 16 at 12 pm EDT
    ➕ Add to your calendar: bit.ly/3PuQozy

  5. In this session, we’ll hear directly from leaders shaping software transparency standards:

    🎙 Steve Springett | Olle E Johansson | Philippe Ombredanne

    Find out how Ecma and OWASP are creating practical solutions for secure, transparent supply chains.

    🗓 Join us: calendar.google.com/calendar/e

  6. 💫 We know you love our series - but we’re taking a break over the summer months.

    No worries, you can catch up on the recordings of previous sessions, and stay informed on the latest CRA-related topics. Check out our full playlist to gain a deeper understanding of issues: youtube.com/playlist?list=PLy7

  7. “If I learned something during the last two years, it was all because of my misconceptions that I had.”

    Fukami's talk is a must-watch for anyone navigating EU tech policy and the Cyber Resilience Act (#CRA).

    Watch now to learn from his experience: youtu.be/7CbHwsKVD80

  8. Trying to understand how the Cyber Resilience Act (#CRA) affects open source?

    Fukami, EU Policy Advisor at the OpenSSF, shared at the session a visual map of the landscape — regulations, actors, responsibilities — and how it all connects.

    🎧 Watch the recording: youtu.be/7CbHwsKVD80

  9. 🗓️ Arnaud Le Hors will introduce the SLSA, its current status, and what’s in the works at the session on 9 June at 5PM CEST.

    SLSA is a security framework for describing and incrementally improving supply chain security, established by industry consensus within OpenSSF.

    Don’t miss it! calendar.google.com/calendar/e

  10. What is the New Legislative Framework (NLF), and how does it shape EU product legislation, including the Cyber Resilience Act (#CRA)?

    In this episode of , Fukami, EU Policy Advisor at the OpenSSF, breaks down the NLF as the legal backbone supporting the enforcement of internal market rules in the EU.

    🎥 Watch the recording to get a clearer understanding of how the NLF provides a common framework for future legislation: youtu.be/7CbHwsKVD80

  11. 💬 “Tech isn't the hardest part. Trust is.”

    In a session, Olle E. Johansson shared that building a trusted global organisation is step one, and only then should we build the tech.
    Want to learn more? Check out the recording! youtu.be/zSsGLJTgWvU

  12. 🔍 Missed the last ?

    Olle E. Johansson joined us for a session on the state of vulnerability management and why the world needs a federated, open, and globally trusted alternative to the NVD.

    🎥 Watch now! youtu.be/zSsGLJTgWvU

  13. 🗓️ The next edition of the will take place online on 12 May!

    We’re diving into the OWASP Software Assurance Maturity Model (SAMM) with Maxim Baele, a SAMM core team member who maintains the model.

    Understanding how manufacturers implement the processes required to build products that are secure by design is essential to understanding how they will consider their due diligence requirements when ingesting components.

    ➕ Add to your calendar! calendar.google.com/calendar/u

  14. In our first edition of the series, Sebastien Heurtematte provided an overview of OCCTET. The recording will be posted shortly.

    In the meantime, check our ORC Community Calendar for the next CRA Monday sessions:

    📆 calendar.google.com/calendar/u

Share on Mastodon

Enter the server where you have an account.