Re: CRA compliance

Gustavo Padovan <[email protected]> Thu, 09 Oct 2025 09:51:44 -0300
Newsgroups dev.linux.lists.kernelci
Message-ID <[email protected]>
Hi Greg,

---- On Thu, 09 Oct 2025 07:48:45 -0300 Greg KH <[email protected]> wrote ---

 > On Thu, Oct 09, 2025 at 07:43:08PM +0900, Arisu Tachibana wrote: 
 > > Hello everyone, 
 > > 
 > > as per the discussion of last week, 
 > > for moving on with the CRA compliance topic. 
 > > I propose to create a private mailing-list called 
 > > [email protected] or [email protected] 
 > > 
 > > any objection ? or suggestion? 
 >  
 > Why is this needed?  Kernel.ci isn't going to be a "steward" of anything 
 > used in a commercial offering, is it?  If not, what would it be for? 

Indeed. Although KernelCI offer free testing services to the community, we are not offering any
products or commercial engagements. So we don't need CRA per se.  However, on a related front
we are working with LF Legal to protect the testing services surfaces as stuff that KernelCI creates
gets to run in internal networks across the industry.

Then for security breaches in KernelCI, it would be a best practice to create kernelci-security@
mailing list for people to report issues and for us to community privately with parties running 
KernelCI infra too.

Best,

- Gus