04 September 2026
EU Cyber Resilience Act reporting obligations begin, while a major npm supply chain attack compromises popular packages.
[$] Governing GNOMEs: how the project's technical decision-making is evolving
GNOME is evolving its technical governance by adopting a teams structure, creating a steering committee, and bootstrapping a Request for Comments (RFC) process. This initiative was spurred by Emmanuele Bassi's presentation at GUADEC 2025 to improve the project's technical decision-making. The project is slowly working on creating more formal structures for this evolution.
LWN · 04 September 2026 · Read the original →
[$] A pause for the Python JIT
Python's steering council (SC) has announced a pause on new development for the experimental just-in-time (JIT) compiler, which was introduced in Python 3.13, allowing only bug and security fixes. This decision was made due to concerns that the JIT's development had proceeded less formally than some might have preferred. The SC's announcement was made in June.
LWN · 04 September 2026 · Read the original →
EU Cyber Resilience Act Reporting Nears
The EU Cyber Resilience Act's first major reporting obligations begin on September 11, 2026, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents within 24 hours of discovery. This deadline applies to products already on the EU market.
digital-strategy.ec.europa.eu · 04 September 2026 · Read the original →
Keyv npm Packages Compromised in Attack
A supply chain attack, starting August 4, 2026, compromised widely used npm packages like 'keyv' and 'cacheable' through a GitHub account takeover, injecting a self-propagating credential-stealing worm. This 'Mini Shai-Hulud' variant affected hundreds of packages with over 500 million weekly downloads.
Snyk · 04 September 2026 · Read the original →
Ericsson Eliminates Private Forks for CRA
Ericsson Software Technology successfully met EU Cyber Resilience Act (CRA) obligations by fundamentally shifting to upstream collaboration, eliminating private forks, and contributing over 1,400 dependency updates and security fixes directly to open source communities. This case study was highlighted in the OpenSSF August 2026 newsletter.
OpenSSF · 04 September 2026 · Read the original →
Eventually, all software engineering becomes a branch of compliance.
5 stories, every Friday
Published here every week. Follow by RSS to get it as it lands.