docs: CRA is hier geen verplichting maar een leidraad — en de tekst zegt dat nu #536
No reviewers
Labels
No labels
accepted
bug
declined
docs
duplicate
enhancement
good first issue
in-progress
needs-info
privacy
security
triage
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
LibreKAT/Ocideck!536
Loading…
Reference in a new issue
No description provided.
Delete branch "docs/cra-als-beschreven"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Records the maintainer's decision on #519 and fixes the wording it made wrong (#532).
Closes #519
Closes #532
The position
The Regulation imposes no obligations here: OciDeck is an open-source project made by the foundation, freely available, and not offered as a service. And we follow it anyway, as a guideline — not because we must, but because it describes reasonably well what maintaining software properly looks like.
Those two sentences belong together. The first stops us taking on a duty that does not exist; the second stops "we don't have to" becoming a reason not to.
Changes
assurance/CRA-2024-2847-positie.md— the position, a guideline table against Annex I Part II with what is open, and five re-evaluation triggers. Inassurance/and notdocs/for the same reason as the ASVS files: steering information, not a product promise.README.md,docs/GLOSSARY.md(×2),docs/SBOM.md,docs/SECURITY_DESIGN.md: "as required by" → "as described in", with the reason stated — we do it because it is part of building software properly. The paragraph inSBOM.mddescribing what the Regulation demands of manufacturers stays, since it is factually correct, now with the note that we are not one.tool/check_service_norms.dart— its header already said it does not measure CRA conformity; it now points at where the reasoning lives.What follows
Three directions came out of the decision, and they are about whether the work is good enough rather than about compliance:
docs_registration_testguards that a document is reachable, not that it is true or followable — thed7b609bfgenerated-guides episode is what that distinction cost last time.Each gets its own issue; the write-up belongs there, not in the position record.
Gates
make check,make check-secrets,make sastall green.