Anwesha Das

Anwesha Das, Red Hat

At the Spring Nordic Software Security Summit, Jimmy Ahlberg presented
“How to talk to your lawyer about open source software and security,”
bridging the gap between developers, business management, and lawyers
navigating CRA compliance. This talk picks up where Jimmy left off — but
from the other side of the fence. What happens when the legalese lands
on a developer’s desk, and someone has to translate it into branch
protection, signed commits, SBOM generation and shiping secure
software?

Red Hat has formally identified itself as an Open Source Software Steward
under the EU Cyber Resilience Act for 15 projects — Ansible, Fedora,
CentOS Stream, Konflux, Quay, StackRox, OKD, crun, hermeto, IIB,
Maistra, OSbuild, Pulp, RamaLama, and sssd. As a member of Red Hat’s
OSAIPO team, I have been part of this journey from the inside: working
alongside the engineers doing the groundwork, changing development
processes to adopt a stronger security posture, and introducing
practices that many contributors were not entirely comfortable with.

This talk is a practitioner’s field report. I will share what it takes
to translate regulation into language developers actually understand and
accept — and where that translation broke down. Specifically, I will
cover:

Focus on Supply Chain Security
Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)