Skip to content
Artwork for Open Source Security
Open Source Security · Yesterday · 40 min

CRA vulnerability reporting with Daniel Thompson

Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra

0:00-40:40

transcript

No transcript — this publisher did not publish one.

show notes

Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra

links1