About this talk
This talk by Roman Zhukov from Red Hat explores the implementation of stewardship practices in open source ecosystems under the EU Cyber Resilience Act (CRA). The session outlines the new role of open source software stewards, emphasizing how they facilitate collaboration between manufacturers and open source projects while addressing compliance obligations. It presents a five-step stewardship implementation model that includes aligning roles, defining principles, and identifying candidate projects, all focused on enhancing security without compromising the autonomy of the community. The discussion highlights the importance of tailored security practices, community engagement, and iterative improvement in achieving effective CRA compliance while maintaining project operations.