Skip to content

docs: reference OpenChain CRA checklist - #414

Open
devashridatta-dotcom wants to merge 1 commit into
cloudsmith-io:masterfrom
devashridatta-dotcom:docs/openchain-cra-reference
Open

docs: reference OpenChain CRA checklist#414
devashridatta-dotcom wants to merge 1 commit into
cloudsmith-io:masterfrom
devashridatta-dotcom:docs/openchain-cra-reference

Conversation

@devashridatta-dotcom

Copy link
Copy Markdown

Summary

  • Adds a short related-resource note to the Package Metadata section for teams mapping SBOM and vulnerability-handling evidence to EU Cyber Resilience Act readiness.
  • Links to the OpenChain CRA Compliance Requirements & Checklist as a community-maintained reference.
  • Clarifies that the checklist is not legal advice or a conformity assessment.

Context

OpenChain maintains Annex D as a living register of organizations and public resources that reference, use, evaluate, or rely on the checklist: https://github.com/OpenChain-Project/CRA-Compliance/blob/main/ANNEX_D_EXTERNAL_REFERENCES_AND_ADOPTION.md

Testing

  • Ran git diff --check.

Copilot AI lite review requested due to automatic review settings September 5, 2026 03:56
@devashridatta-dotcom
devashridatta-dotcom requested a review from a team as a code owner September 5, 2026 03:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a brief documentation note in the Package Metadata section to help teams relate SBOM and vulnerability-handling evidence to EU Cyber Resilience Act (CRA) readiness, pointing to the OpenChain CRA Compliance Requirements & Checklist and clarifying it is not legal advice.

Changes:

  • Added a related-resource reference to the OpenChain CRA Compliance Requirements & Checklist for organizing compliance evidence.
  • Added an explicit disclaimer that the checklist is not legal advice or a conformity assessment.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants