generated from ossf/project-template
-
Notifications
You must be signed in to change notification settings - Fork 19
Open
Description
I am concerned by item 8 in the CRA Stewards One-Pager:
Perform due diligence on software components used by the project before publication. Consider the Concise Guide for Evaluating Open Source Software and the Open Source Project Security Baseline.
Where does the requirement to perform due diligence come from? I can't find anything in Article 24 of the CRA which suggests this is a requirement.
Performing due diligence is good, and should be encouraged, but I don't think this checklist is the right place for it unless it is a direct requirement of the CRA.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels