Community News

ORC’s First Whitepaper on Open Source Software Stewards and the Cyber Resilience Act

Thursday, February 12, 2026 - 08:44 by Shanda Giacomoni

The adoption of the EU Cyber Resilience Act (CRA) represents a major shift in how cybersecurity responsibilities are defined across the software ecosystem. For the first time, the regulation explicitly recognises Open Source Software Stewards as a distinct category of legal actors, separate from manufacturers, and subject to a tailored set of obligations.

Scaling the Open VSX Registry responsibly with rate limiting

Thursday, February 12, 2026 - 05:38 by Natalia Loungou

The Open VSX Registry has become widely used infrastructure for modern developer tools. That growth reflects strong trust from the ecosystem, and it brings a shared responsibility to keep the Registry reliable, predictable, and equitable for everyone who depends on it.

Eclipse Theia 1.68 Releases: News and Noteworthy

Thursday, February 12, 2026 - 03:55 by Jonas Helming

Eclipse Theia 1.68 lands with Copilot integration, a significantly improved Architect Plan Mode, Skill Support, Shell Execution,an upgraded Coder Agent Mode (Next), improved UI Testing, and more. Read the highlights (and note it’s the RC for the 2026-02 community release).

Image for 
<span>Eclipse Theia 1.68 Releases: News and Noteworthy</span>
 News item.

Enterprise Java Persistence beyond the JPA mindset

Thursday, February 12, 2026 - 03:32 by Natalia Loungou

Otavio Santana explains why JPA remains relevant, but no longer sits at the centre of every persistence decision and how Jakarta EE 12 reflects the realities of modern, polyglot systems.

Please don’t make your CRA due diligence a DoS attack!

Tuesday, February 10, 2026 - 15:01 by Shanda Giacomoni

When carrying out the required due diligence for all components in a product, there’s a real risk of unintentionally contributing to a denial-of-service attack on the open source maintainers. Let’s work together to make sure it doesn’t happen. The Open Regulatory Compliance working group is starting to work on a best current practice, and we’d like to tell you more about this important project.

Generating an SBOM is not enough for Java teams

Monday, February 9, 2026 - 06:04 by Natalia Loungou

Attend the session "CRA, NIS2, DORA: What senior Java engineers must deliver before 2027" at OCX to gain practical guidance on making your Java systems SBOM-ready ahead of CRA enforcement.

From Code to Compliance at FOSDEM 2026

Friday, February 6, 2026 - 10:18 by Shanda Giacomoni

Over the FOSDEM week, one message became unmistakably clear: attestations and due diligence are no longer optional side topics; they are becoming foundational to the sustainability of open source in a regulated world.

If You Depend on Eclipse Platform Technologies, Now Is the Time to Act

Friday, February 6, 2026 - 10:02 by Thomas Froment

If your products rely on Eclipse Platform technologies, this matters.
🧭 Eclipse Platform (aka RCP) components remain widely deployed, but the model sustaining them is under pressure.
From long term maintenance to EU Cyber Resilience Act compliance, relying on open source platform technologies for free is no longer a responsible option.

👇 Read the full article to understand the risk and the concrete ways to act 👇


 

Image for 
<span>If You Depend on Eclipse Platform Technologies, Now Is the Time to Act</span>
 News item.

SDV Newsletter 1/2026: Turning momentum into milestones

Tuesday, February 3, 2026 - 06:30 by Diana Kupfer

2026 will be the year we turn momentum into milestones. The first milestone has already been reached: At CES in Las Vegas, 32 automotive companies signed the Memorandum of Understanding for open source collaboration.

From tested to "trustable": Rethinking software assurance at OCX 2026

Monday, February 2, 2026 - 13:10 by Natalia Loungou

Recent global outages reveal that even well-tested and certified software can fail at scale, underscoring a growing trust gap in the software supply chain. This will be explored in John Ellis’ OCX session, “Rebuilding trust: From open source to open accountability.”

ORC Monthly: A Strong Start to 2026 for Open Source and CRA Compliance

Thursday, January 29, 2026 - 15:24 by Shanda Giacomoni

As we publish this month’s ORC update, the community is right in the middle of Open Source Week in Brussels. With FOSDEM and a packed schedule of policy, compliance, and community discussions underway, the energy and relevance of our work has never been clearer. That momentum is echoed by the strong response to our Code & Compliance event, which sold out! This signals a community that is growing, engaged, and ready to build on its progress.

Strengthening supply-chain security in Open VSX

Wednesday, January 28, 2026 - 09:06 by Natalia Loungou

The Open VSX Registry is core infrastructure in the developer supply chain, delivering extensions developers download, install, and rely on every day. As the ecosystem grows, maintaining that trust matters more than ever.

FOSDEM and EU Open Source Week 2026: Key Events for the ORC Community

Monday, January 12, 2026 - 10:13 by Shanda Giacomoni

Late January in Brussels has become an important moment for anyone working at the intersection of open source and European regulation. For the ORC community, this week is particularly relevant. The Cyber Resilience Act (CRA) is moving from interpretation to implementation, and many of the conversations happening during this week focus on what that means in practice.