CRA stewardship: LF AI & Data is supported under the Linux Foundation CRA stewardship framework. The LF AI & Data Foundation’s CRA steward is The Linux Foundation and its policy is available at https://www.linuxfoundation.org/security. Most of the individual LF AI projects report up to the parent LF Projects, LLC but this can be checked on a per project basis in LFX PCC (see Operations->Project Definition->Legal Details - or ask at support@linuxfoundation.org)
Resources: Understanding the EU Cyber Resilience Act (CRA) (LFEL1001) - Linux Foundation - Education, which is a free course that provides an in-depth look at the various roles and requirements for CRA compliance.
If you believe you have found a security vulnerability in any of our repository, please report it to us through coordinated disclosure.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, please send an email to the active maintainer at marvin.hansen@gmail.com.
Please include as much of the information as you can to help us better understand and resolve the issue:
We aim to respond within 7 to 10 working days to reported security vulnerabilities.
We identify every known security vulnerability after it was closed in the release notes,