Skip to content

Latest commit

 

History

22 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

CRA Stewardship Guidelines and Templates

This repository contains guidelines and templates for open source projects for which Red Hat, Inc. acts as an open source software steward under the EU Cyber Resilience Act (CRA) (Regulation 2024/2847).

What is the EU Cyber Resilience Act?

The EU Cyber Resilience Act establishes cybersecurity requirements for products with digital elements sold in the EU. It introduces the concept of an Open Source Software Steward (Article 3(14)) — an organization that provides support, oversight, or coordination for open source projects without placing those products on the market commercially.

Red Hat fulfills this steward role for a number of open source projects, accepting defined obligations around vulnerability management, security disclosures, and coordination with the broader open source community.

Repository Contents

Path Description
Templates/Security_MD_template.md Template SECURITY.md for CRA-stewarded projects
Guidelines/eu-cra-incident-and-vulnerability-reporting-guidelines.md Guidelines for stewarded projects on reporting actively exploited vulnerabilities and severe incidents to Red Hat

Using the Templates

SECURITY.md

Every CRA-stewarded project should have a SECURITY.md file at the root of its repository. This file tells users and researchers how to report vulnerabilities and what to expect in response.

Steps to adopt:

  1. Copy Templates/Security_MD_template.md to SECURITY.md in your project repository.
  2. Replace all <!-- ... --> placeholder comments with project-specific values:
    • Security contact email address
    • Response timeline
    • Link to the latest supported version
    • Link to your support matrix and vulnerability management policy
  3. Remove or fill in the optional sections (GPG key, disclosure status).

The template already includes the required EU Cyber Resilience Act — Open Source Steward Statement identifying Red Hat as the steward and referencing the CRA regulation.

Projects Under Red Hat CRA Stewardship

As of September 2026, Red Hat has formally identified itself as an Open Source Software Steward. The list below is not exhaustive — the following projects were selected for the initial pilot:

Project Repository
Ansible Ansible ansible/ansible
Fedora src.fedoraproject.org
CentOS Stream CentOS Stream redhat/centos-stream
Konflux Konflux konflux-ci
Quay Quay quay/quay
StackRox StackRox stackrox/stackrox
OKD OKD okd-project/okd
crun crun containers/crun
hermeto hermetoproject/hermeto
IIB IIB release-engineering/iib
Maistra Maistra maistra
OSbuild OSbuild osbuild/osbuild
Pulp Pulp pulp
RamaLama RamaLama containers/ramalama
sssd sssd SSSD/sssd

For more details, see Red Hat's CRA stewardship guidelines.

Contact

For questions about CRA stewardship obligations or this repository, contact Red Hat at cra-steward@redhat.com.

About

Red Hat Product Security CRA repository for templates, guides and other sharable resources.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors