#orcwg — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #orcwg, aggregated by home.social.
-
🚦 We’re in the final stretch: 3 months until #CyberResilienceAct reporting requirements hit.
According to ONEKEY, 37% of companies see the 24-hour reporting rule as their number 1 challenge. Are you ready?👉 Learn more: http://orcwg.org/cra
-
The ORC panel at #OCX26 explored how the #CRA is being implemented across different ecosystems. The discussion highlighted the complexity of aligning regulatory requirements with diverse technical environments.
🎥 Watch the recording: https://hubs.la/Q04fXP250
⭐ Read the highlights: https://hubs.la/Q04fXLkX0 -
Just arrived at #OCX26 in #brussels 🧳Looking forward to meet the #community! Join @ixchelruiz and my talk (https://www.ocxconf.org/event/2026/agenda?session=42a01f9e-1f26-4fba-9851-59afadcd689c) on #CRA and other regulations and how to comply with them. #java #eclipse #Orcwg #OpenSource #Compliance
-
Just arrived at #OCX26 in #brussels 🧳Looking forward to meet the #community! Join @ixchelruiz and my talk (https://www.ocxconf.org/event/2026/agenda?session=42a01f9e-1f26-4fba-9851-59afadcd689c) on #CRA and other regulations and how to comply with them. #java #eclipse #Orcwg #OpenSource #Compliance
-
What did Log4Shell teach us about securing open source?
Join the ORC WG on Monday to explore the lessons from Log4Shell and what a CRA-ready Log4j looks like.
📆 March 16 at 12 pm EDT
➕ Add to your calendar: https://buff.ly/GZ8m6Gv -
What did Log4Shell teach us about securing open source?
Join the ORC WG on Monday to explore the lessons from Log4Shell and what a CRA-ready Log4j looks like.
📆 March 16 at 12 pm EDT
➕ Add to your calendar: https://buff.ly/GZ8m6Gv -
Log4Shell revealed just how deeply open source runs through the global software supply chain—and how hard it can be to respond when a critical dependency fails.
Join the ORC WG for the next #CRAMondays to explore the lessons from Log4Shell and what it takes to build a CRA-ready Log4j.
📆 March 16 at 12 pm EDT
➕ Add to your calendar: https://bit.ly/3PuQozy -
Log4Shell revealed just how deeply open source runs through the global software supply chain—and how hard it can be to respond when a critical dependency fails.
Join the ORC WG for the next #CRAMondays to explore the lessons from Log4Shell and what it takes to build a CRA-ready Log4j.
📆 March 16 at 12 pm EDT
➕ Add to your calendar: https://bit.ly/3PuQozy -
Want to find out more about the Cyber Resilience Act or the Open Regulatory Compliance Working Group?
We will be at #EmbeddedWorld2026, ready to answer all your questions and talk about getting involved with the working group!
Find us at booth 4-554 in hall 4.
See you there!
-
Listen to me and Anthony summarising our experiences from EU Open Source Week and FOSDEM!
Join us for SBOM Focus in Stockholm Friday April 10, 2026
https://sbomfocus.eu -
Listen to me and Anthony summarising our experiences from EU Open Source Week and FOSDEM!
Join us for SBOM Focus in Stockholm Friday April 10, 2026
https://sbomfocus.eu -
The Open Regulatory Compliance Working Group will be at Embedded World 2026!
🌐 Visit the #EclipseFdn booth 4-554 in hall 4 to dive deeper into how #ORCWG is driving meaningful change in the world of open source compliance.
-
⏰ Final call! Our ORC has received some amazing name suggestions, but there’s still time to share yours!
We’re collecting ideas until 28 November, so if you haven’t joined in yet, now’s your chance.
💚 Help us give our ORC the perfect name to represent the Open Regulatory Compliance community.
-
The countdown is on!
Manufacturers have less than a year to comply with the #CyberResilienceAct’s vulnerability reporting requirements.
📘 Explore our resources to help your team prepare: https://orcwg.org/cra/
#CRA #CyberResilience #ORCWG -
🇮🇹 Happening this week in Bolzano! Join the #EclipseFdn sessions on 7 Nov:
📍How #ORCWG helps industry meet the #CRA (Francisco Carneiro)
📍Free of charge != cost-free (Carmen Delgado)
📍How Oniro builds seamless global smart ecosystems (Ignacio Ahedo) -
🇮🇹 Happening this week in Bolzano! Join the #EclipseFdn sessions on 7 Nov:
📍How #ORCWG helps industry meet the #CRA (Francisco Carneiro)
📍Free of charge != cost-free (Carmen Delgado)
📍How Oniro builds seamless global smart ecosystems (Ignacio Ahedo) -
📅 Don't miss these #EclipseFdn sessions on 7 Nov at #SFSCON:
📍How #ORCWG helps industry meet the #CRA - Francisco Carneiro
📍Free of charge != cost-free - Carmen Delgado
📍How Oniro builds seamless global smart ecosystems - Ignacio AhedoRegister today! https://pretix.eu/noi-digital/sfscon25/
-
📅 Don't miss these #EclipseFdn sessions on 7 Nov at #SFSCON:
📍How #ORCWG helps industry meet the #CRA - Francisco Carneiro
📍Free of charge != cost-free - Carmen Delgado
📍How Oniro builds seamless global smart ecosystems - Ignacio AhedoRegister today! https://pretix.eu/noi-digital/sfscon25/
-
Have you recently checked the FAQ about the Cyber Resilience Act (#CRA)?
We want your input on open CRA questions.
Share your feedback! https://github.com/orcwg/cra-hub/blob/main/faq.md
-
📢 New on the ORC website!
Stay informed with the latest insights on #opensource and regulatory #compliance.
The ORC blog features updates, perspectives, and practical guidance from across the community, helping you navigate compliance in a fast-evolving landscape.
🔍 Read the latest posts: https://orcwg.org/blog/
-
Did you know?
#ORCWG is currently developing a series of white papers focused on key aspects of cybersecurity and open source.
📢 If you're interested in contributing your expertise or reviewing drafts, we welcome your participation. Learn more and get involved on GitHub: https://github.com/orcwg/orcwg/blob/main/cyber-resilience-sig/deliverables.md#3-white-papers
-
💫 We know you love our #CRAMondays series - but we’re taking a break over the summer months.
No worries, you can catch up on the recordings of previous sessions, and stay informed on the latest CRA-related topics. Check out our full playlist to gain a deeper understanding of #CRA issues: https://www.youtube.com/playlist?list=PLy7t4z5SYNaT-DjqGR0ORSSZGZYW8qmRs
-
✨ Curious about the #CRA? Why should open source maintainers care?
💻 Check this video from the maintainers month webinar to learn how it affects open source software and the importance for those monetising it.
Participate in this conversation: https://hubs.la/Q03wcZ_x0
-
Timo Perala (Nokia) will discuss #ORCWG during his #CRA talk at Open Source Summit Europe.
Learn more about Timo's session: https://osseu2025.sched.com/event/25VmN/the-cra-where-are-we-six-months-after-its-approval-timo-perala-nokia?iframe=no&w=100%&sidebar=yes&bg=no
-
Are you hoping to learn more about the EU’s Cyber Resilience Act (CRA)?
🎥 Explore our playlist of webinar and community call recordings, featuring insights, updates, and discussions from the #ORCWG community: https://bit.ly/42mJm4x
-
🇪🇺 The EU’s Cyber Resilience Act (#CRA) is reshaping how open source projects approach risk and compliance.
📌 Join our webinar on 24 June to learn about the resource the ORC community is developing to support the open source projects and users with CRA compliance.
Don’t miss it! https://www.crowdcast.io/c/cra2506 -
Trying to understand how the Cyber Resilience Act (#CRA) affects open source?
Fukami, EU Policy Advisor at the OpenSSF, shared at the #CRAMondays session a visual map of the landscape — regulations, actors, responsibilities — and how it all connects.
🎧 Watch the recording: https://youtu.be/7CbHwsKVD80
-
🎥🔴 Don’t miss this on-demand webinar from the #ORCWG covering the EU’s Cyber Resilience Act (CRA) standards, including their production timeline! https://buff.ly/3QmMYMO
-
What is the New Legislative Framework (NLF), and how does it shape EU product legislation, including the Cyber Resilience Act (#CRA)?
In this episode of #CRAMondays, Fukami, EU Policy Advisor at the OpenSSF, breaks down the NLF as the legal backbone supporting the enforcement of internal market rules in the EU.
🎥 Watch the recording to get a clearer understanding of how the NLF provides a common framework for future legislation: https://youtu.be/7CbHwsKVD80
-
💬 “Tech isn't the hardest part. Trust is.”
In a #CRAMondays session, Olle E. Johansson shared that building a trusted global organisation is step one, and only then should we build the tech.
Want to learn more? Check out the recording! https://youtu.be/zSsGLJTgWvU -
Do all #opensource projects have an open source software steward?
Not all open source projects have a steward, and the ORC community is actively discussing this topic. Current discussions suggest that most projects don’t meet the criteria for having a steward, as a steward must be a "legal person" (Art. 3), such as a company, which excludes many community-driven projects.
Join this conversation on GitHub! https://github.com/orcwg/cra-hub/issues/170
-
🇪🇺 The EU's Cyber Resilience Act (#CRA) is different from previous compliance requirements. For the first time, full supply chain compliance will be required for all products with digital elements sold in the European market.
💡 If you manufacture, maintain, or steward #opensource software and are unclear about how the CRA might impact you, check out the #ORCWG's GitHub for discussions! https://github.com/orcwg/cra-hub
-
Can a solo maintainer be considered to be an #opensource software steward?
Check our ongoing #CRAFAQ discussion on GitHub and share your thoughts and contributions!
-
Are you worried about how the EU’s Cyber Resilience Act (CRA) might impact you? Are you considering shutting down your #opensource projects?
➡️ Discussion on this topic is ongoing. The prevailing opinion is that most open source developers won’t be significantly affected, meaning you don’t need to shut down your open source projects because of the CRA.
Explore the reasons for it, and engage with the community discussion: https://github.com/orcwg/cra-hub/issues/133
-
Are you hoping to learn more information about the EU's Cyber Resilience Act (#CRA)?
🎥 Explore our playlist of webinar and community call recordings, featuring insights, updates, and discussions from the #ORCWG community: https://bit.ly/42mJm4x
-
🌐 Don’t miss out on the chance to learn more about how the #opensource community through the #ORCWG is responding to the challenges posed by the EU's Cyber Resilience Act (#CRA).
Register to attend this webinar, taking place on 28 April! https://www.crowdcast.io/c/orc-28042025
-
🚨 One week to go!
Juan Rico will explore how the open source community through the #orcwg is responding to the challenges posed by the EU's Cyber Resilience Act (CRA).
-
🎙 Don't miss the #orcwg first in-person meeting focused on the implementation of the EU CRA. This hands-on workshop will focus on vulnerability management, the CRA’s attestation program and its potential to help make open source more sustainable.
https://www.eventbrite.com/e/orc-wg-workshop-tickets-1105475510009?aff=ebdsoporgprofile -
@swheritage is a founding member of the @EclipseFdn ’s new Open Regulatory Compliance Working Group (#ORCWG), dedicated to helping #OpenSource projects navigate emerging regulatory requirements like the #CRA.
👉 Learn more:
https://www.softwareheritage.org/2024/10/01/software-heritage-joins-orcwg/ -
Landmark legislation is reshaping the #OpenSource ecosystem. @swheritage joined the Open Regulatory Compliance Working Group (#ORCWG) to ensure that innovation & compliance go hand-in-hand.
More from organizers @EclipseFdn 👇👇👇
-
🤲 @swheritage is joining forces with #OpenSource foundations & global leaders to work on some of the thorniest regulatory issues in tech.
-
We’re excited to announce the formal launch of the Open Regulatory Compliance Working Group! Learn how global tech companies and open source foundations are working together to navigate software regulations in our news release: https://hubs.la/Q02QPVVj0 #ORCWG #CyberResilienceAct