Conversation

The "good" people at Emerson for some reason couldn't think for themselves when I responded to them on behalf of and instead continue and send the same questions to the project with the same "demands".

"This is a gentle reminder regarding our earlier request for your input on the cybersecurity risk assessment of the software component β€œlibssh2” version 1.11.0, as part of our compliance efforts with the EU Cyber Resilience Act (CRA)."

3
4
1

I have also offered them a contract to help them answer these questions for curl, but they have not yet taken me up on that. As time passes, it seems more and more unlikely that they will.

1
0
0

@bagder

I just think it is so funny of them to use "gentle reminder" to "request" others to save their bacon for free.

Their internal reasoning and strategizing to come up with that would be interesting to know.

1
0
0

@tsvenson @bagder This is worded exactly the way Ive seen when dealing with paid software licenses.

They're evidently mixing supported software where they have a paid license and FOSS software into the same risk analysis process which is stupid for obvious reasons.

2
0
0

@varx @tsvenson in this case, since I have already been in contact with them about exactly that, they can no longer plead ignorance. They now KNOW but they still decide to push forward like this.

0
0
1

@bagder But, but… their deadlines!? 🀣

0
0
0

@bagder The libtiff project also got the same request from Emerson (sent to the listserv owner) for libtiff, mentionning a totally antiquated libtiff version (3.6.1). I didn't bother answering them

0
0
1
@bagder I know that other project(s) received EXACTLY the same requests from Emerson.

This is just disgrace for a big company like Emerson.
0
0
0

@varx @tsvenson @bagder How to handle the CRA?
1. Panic,
2. Gather all SBOMs,
3. Send similar emails to all discovered parties,
4. Enjoy responses.

0
0
1

@bagder Today they sent one for APT.

https://lists.debian.org/deity/2025/08/msg00010.html

Oh I see they even have HTML, neither Thunderbird nor Neomutt (duh) rendered that :D

Attached is my reply...

1
0
0

@juliank just to nitpick: it is "subject to the CRA" for them

1
0
0

@bagder oh I guess should have said the APT project as opposed to the APT code they got from somewhere :D

0
0
0