Skip to content

Conversation

@SecurityCRob
Copy link
Contributor

Corrected the CRA Playbook README.

Corrected the CRA Playbook README.

Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
@SecurityCRob SecurityCRob requested a review from torgo November 25, 2025 18:07
@SecurityCRob SecurityCRob added documentation Improvements or additions to documentation for review artifact for review and commentary labels Nov 25, 2025
Added an executive summary and clarified roles of Open Source Stewards under the CRA.

Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
@@ -0,0 +1,49 @@
# LF CRA Playbook #

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I feel like maybe a one-sentence intro like "This document relates to how LF projects need to do to respond to the European Cyber Resilience Act (CRA)." ... but maybe I'm just over-thinking it.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was not deeply involved in the drafting of this (unfortunately), so I can only judge based on this draft here. Please ignore or correct me if I am going off track:

I think you have a point, but I would not limit it to projects by only calling out projects specifically. If is a valid statement that this is a playbook describing how all actors related to Linux Foundation projects respond to the Cyber Resilience Act: projects (contributors), manufacturers (downstream users), and stewards (the Linux Foundation and OpenSSF).

Again, just my 2 cents.

SecurityCRob and others added 4 commits December 1, 2025 08:53
Co-authored-by: Daniel Appelquist <dan@torgo.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Daniel Appelquist <dan@torgo.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Daniel Appelquist <dan@torgo.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Daniel Appelquist <dan@torgo.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Copy link
Contributor

@gkunz gkunz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

couldn't resist fixing some of those spelling errors. Two additional comments.


Take free course [Understanding the EU Cyber Resilience Act (CRA) (LFEL1001)](https://training.linuxfoundation.org/express-learning/understanding-the-eu-cyber-resilience-act-cra-lfel1001/) to learn more.

## Executive Summary ##
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My feeling when reading this: This section is already goes in some detail regarding the role of Stewards. In addition, there is a very short section on Stewards further below. So, from a structure perspective, how about moving the heading "Steward" to right after the first paragraph and also more the text from below up here.

@@ -0,0 +1,49 @@
# LF CRA Playbook #

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was not deeply involved in the drafting of this (unfortunately), so I can only judge based on this draft here. Please ignore or correct me if I am going off track:

I think you have a point, but I would not limit it to projects by only calling out projects specifically. If is a valid statement that this is a playbook describing how all actors related to Linux Foundation projects respond to the Cyber Resilience Act: projects (contributors), manufacturers (downstream users), and stewards (the Linux Foundation and OpenSSF).

Again, just my 2 cents.

SecurityCRob and others added 9 commits December 3, 2025 13:19
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Co-authored-by: Georg Kunz <georg.kunz@ericsson.com>
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation for review artifact for review and commentary

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants