Re: CRA compliance

Gustavo Padovan <[email protected]> Thu, 09 Oct 2025 14:56:04 -0300
Newsgroups dev.linux.lists.kernelci
Message-ID <[email protected]>

---- On Thu, 09 Oct 2025 10:06:42 -0300 Greg KH <[email protected]> wrote ---

 > On Thu, Oct 09, 2025 at 09:51:44AM -0300, Gustavo Padovan wrote: 
 > > Hi Greg, 
 > > 
 > > ---- On Thu, 09 Oct 2025 07:48:45 -0300 Greg KH <[email protected]> wrote --- 
 > > 
 > >  > On Thu, Oct 09, 2025 at 07:43:08PM +0900, Arisu Tachibana wrote: 
 > >  > > Hello everyone, 
 > >  > > 
 > >  > > as per the discussion of last week, 
 > >  > > for moving on with the CRA compliance topic. 
 > >  > > I propose to create a private mailing-list called 
 > >  > > [email protected] or [email protected] 
 > >  > > 
 > >  > > any objection ? or suggestion? 
 > >  > 
 > >  > Why is this needed?  Kernel.ci isn't going to be a "steward" of anything 
 > >  > used in a commercial offering, is it?  If not, what would it be for? 
 > > 
 > > Indeed. Although KernelCI offer free testing services to the community, we are not offering any 
 > > products or commercial engagements. So we don't need CRA per se.  However, on a related front 
 > > we are working with LF Legal to protect the testing services surfaces as stuff that KernelCI creates 
 > > gets to run in internal networks across the industry. 
 >  
 > That's great, but that has nothing to do with the CRA :) 

FWIW, I just pushed a PR adding some remarks about reporting security vulnerabilities to KernelCI:

https://github.com/kernelci/kernelci-project/pull/553

Best,

- Gus