Building an Understanding of Voluntary Security Attestations and Their Role in Sustaining Open Source Communities
In the context of the EU’s Cyber Resilience Act, Article 25, these could be documents that describe the security practices, processes, attributes, or assurances associated with an open source project. They could be publicly shared, perhaps in a code repository or alongside a build binary, or they could be privately shared, for example, as FreeBSD has done. However, we don’t really know what they should be, just yet, and defining that together is the purpose of this new project.