Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Open Source

04 September 2026

EU Cyber Resilience Act reporting obligations begin, while a major npm supply chain attack compromises popular packages.

One week of Open Source, 5 stories, as published.

Governance

[$] Governing GNOMEs: how the project's technical decision-making is evolving

GNOME is evolving its technical governance by adopting a teams structure, creating a steering committee, and bootstrapping a Request for Comments (RFC) process. This initiative was spurred by Emmanuele Bassi's presentation at GUADEC 2025 to improve the project's technical decision-making. The project is slowly working on creating more formal structures for this evolution.

Why it matters — Formalizing technical governance structures like teams, steering committees, and RFC processes can help large open source projects make more consistent and transparent decisions, improving project health and predictability.

LWN · 04 September 2026 · Read the original →

Governance

[$] A pause for the Python JIT

Python's steering council (SC) has announced a pause on new development for the experimental just-in-time (JIT) compiler, which was introduced in Python 3.13, allowing only bug and security fixes. This decision was made due to concerns that the JIT's development had proceeded less formally than some might have preferred. The SC's announcement was made in June.

LWN · 04 September 2026 · Read the original →

Regulation

EU Cyber Resilience Act Reporting Nears

The EU Cyber Resilience Act's first major reporting obligations begin on September 11, 2026, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents within 24 hours of discovery. This deadline applies to products already on the EU market.

Why it matters — Companies selling products into the EU must establish rapid vulnerability identification and reporting processes by September 11, 2026, or face significant penalties and potential product withdrawal.

digital-strategy.ec.europa.eu · 04 September 2026 · Read the original →

Supply Chain

Keyv npm Packages Compromised in Attack

A supply chain attack, starting August 4, 2026, compromised widely used npm packages like 'keyv' and 'cacheable' through a GitHub account takeover, injecting a self-propagating credential-stealing worm. This 'Mini Shai-Hulud' variant affected hundreds of packages with over 500 million weekly downloads.

Why it matters — Engineers must audit dependency trees, pin to versions published before August 4, 2026, and rotate all potentially exposed credentials to mitigate the spread of credential-stealing malware.

Snyk · 04 September 2026 · Read the original →

Governance

Ericsson Eliminates Private Forks for CRA

Ericsson Software Technology successfully met EU Cyber Resilience Act (CRA) obligations by fundamentally shifting to upstream collaboration, eliminating private forks, and contributing over 1,400 dependency updates and security fixes directly to open source communities. This case study was highlighted in the OpenSSF August 2026 newsletter.

Why it matters — Companies can reduce compliance burdens and security risks under regulations like the CRA by actively contributing upstream to open source projects, rather than maintaining costly private forks.

OpenSSF · 04 September 2026 · Read the original →

Eventually, all software engineering becomes a branch of compliance.

5 stories, every Friday

Published here every week. Follow by RSS to get it as it lands.

← Previous issue Next issue →