Sveriges mest populära poddar
What's in the SOSS? An OpenSSF Podcast
What's in the SOSS? An OpenSSF Podcast

Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo

19 min•25 augusti 2026

Om avsnittet

In this episode of What's in the SOSS, host Sally Cooper sits down with returning champion Dave Russo, Policy and Standards Lead at Red Hat’s Open Source and AI Program Office, to unpack the European Union’s Cyber Resilience Act (CRA). Together, they explore the stark realities of the 2026 CRA Awareness and Readiness Report, exposing why three-quarters of North American tech companies remain completely unaware of the strictest cybersecurity mandate in history. Dave breaks down the hidden $250,000-per-release financial toll of maintaining private forks, the crucial legal distinction between software manufacturers and open source stewards, and Red Hat's framework for "champion stewardship." Whether you are facing the upcoming September 2026 vulnerability reporting platform launch or preparing for full December 2027 enforcement, this conversation delivers clear, actionable guidance to get your organization compliant, collaborative, and secure. 

Chapters:

  • 00:25 - Welcome & Introductions
  • 01:28 - Meet Dave Russo
  • 02:01 - The Global CRA Awareness Gap
  • 04:46 - The Hidden Cost of Private Forks
  • 07:32 - Manufacturer vs. Open Source Steward
  • 09:09 - Red Hat's Light vs. Champion Stewardship
  • 11:37 - Crucial CRA Deadlines Explained
  • 13:51 - Actionable Compliance Steps Today
  • 16:47 - Rapid Fire Fun

Episode links:

What's in the SOSS? An OpenSSF Podcast med OpenSSF finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.