Vulnerability data is broken in the same way software supply chains were a decade ago: fragmented, duplicative, and impossible to trust without redoing the work yourself. The EU Cyber Resilience Act (CRA) is about to make that a legal problem, not just a technical one, as organizations are scrambling to prove they can track, report, and respond to vulnerabilities across their software supply chain. AboutCode is tackling this head-on with three interlocking efforts.

First, data: vulnerability information treated as a shared, curated and verified commons, deduplicated and traceable to source. This enables every team to stop re-triaging the same advisory from scratch all over again, and can produce the audit trail the CRA demands, backed by automation that correct data enables.
Second, standards: open, ecosystem-agnostic identifiers that let any tool, database, or organization refer to the same vulnerability the same way, closing a gap that has quietly wasted years of collective effort and complicated CRA reporting across fragmented toolchains. This means PURL and VERS, and a new identifier for security advisories.
Third, tooling: practical and trustworthy open source software that turns CRA and other regulatory compliance obligations from a manual paperwork burden into an automatable pipeline anyone can adopt.
Attendees will leave with a clear framework for evaluating their own security data supply chain and meeting CRA obligations, and a new foundation for software supply chain security, using data you can trust, standards you can share, and tools you can run.