Posts

This profile is from a federated server and may be incomplete. Browse more on the original instance.

webmink, to medical
@webmink@meshed.cloud avatar

The #CRA has proven that @osi needs a full-time #policy analyst to serve the #OpenSource community in Europe. Do you know someone who would flourish in that role? Here is the job posting!
https://opensource.org/about/team/vacancy-osi-policy-analyst

webmink, to random
@webmink@meshed.cloud avatar

Woke up to find has totally destroyed their app on all our phones, the only way to control their products, and left it with no play queue, no playlists, no widget controls, and when contacted for support pretends it's somehow better.

webmink, to random
@webmink@meshed.cloud avatar

Johnson, of course, knew the voter suppression he initiated was performative, but it's still iconic to see him turned away from the polls today because he didn't have ID.
https://www.theguardian.com/uk-news/article/2024/may/02/minister-sorry-as-veterans-find-id-card-not-valid-for-english-elections

webmink, to medical
@webmink@meshed.cloud avatar

The @EU_Commission has launched a public consultation on the rules defining the European system (aka regulation 1025). The top-line for me is it completely ignores while making both engagement in standardisation and use of standards very hard for open source community members.

Unsurprisingly, the consultation's survey makes it extremely hard to tell them this! I think @osi will be attaching a letter to its input! The deadline is July 25.

https://discuss.opensource.org/t/time-to-fix-the-rules-about-european-standards/284?u=webmink

webmink,
@webmink@meshed.cloud avatar
boud,
@boud@framapiaf.org avatar

@webmink

Thanks! I checked through those searching for an answer the question of "How much of 'all' software is FOSS or depends on FOSS?", but I could only find one study, not a range of studies - Synopsys - whose full report requires email registration (and it's not a peer-reviewed research paper):
https://www.synopsys.com/blogs/software-security/open-source-trends-ossra-report.html

The Fraunhofer/OFE report is solid, but doesn't seem to answer this particular question:
https://ec.europa.eu/newsroom/dae/redirection/document/79021

Do you know of any other study than the Synopsys one?

webmink, to random
@webmink@meshed.cloud avatar

Wait, so Hashicorp broke Terraform to lure IBM, a Linux Foundation platinum member?

mcdanlj,
@mcdanlj@social.makerforums.info avatar

@webmink That assumes there was only one suitor. It's conceivable that they used it to increase their valuation with another suitor in a bidding war. Looking at the valuation I'd be surprised if this were a single-party negotiation.

If IBM reverses course and moves the acquired products back to an open source license, I'd expect that the license change was used as leverage in negotiations, either with another suitor, or as the "stick" part of "carrot and stick".

If IBM keep it fauxpen source substantially post-acquisition, I will doubt my current construction.

webmink, to opensource
@webmink@meshed.cloud avatar

A small change to the most recent (Parliament-approved) version of the Cyber Resilience Act () is the addition of a requirement that software be "openly shared" in order for the European Union to consider it in relation to the CRA.

https://the.webm.ink/openly-shared

webmink, to opensource
@webmink@meshed.cloud avatar

If you heard my comments yesterday about the need to revise the EU rules on #standards (reg 1025) so they don't discriminate against #OpenSource, you may also want to add your comments to the topic in @osi's new Discourse forum at https://discuss.opensource.org/t/time-to-fix-the-rules-about-european-standards/284 (free sign-up required to post unless you're already an OSI member).

webmink, to opensource
@webmink@meshed.cloud avatar

Looks like the big #OpenSource foundations have got tired of being blocked by the #standards massif amd the @EU_Commission over #CRA standards and are organising their own initiative.

https://eclipse-foundation.blog/2024/04/02/open-source-community-cra-compliance/

Sweetshark,
@Sweetshark@chaos.social avatar

@luis_in_brief @webmink One thing well done about SLSA is that is has levels, and the lower ones are reasonably easy to archive. Thus it easier to convince TPTB to invest "just a little" to start moving in the right direction.

Recommend to consider something similar.

luis_in_brief,
@luis_in_brief@social.coop avatar

@Sweetshark @webmink I don't have my written analysis handy, and it's been a couple of years, but last I looked it was essentially impossible for solo maintainers (i.e., the median maintainer) to achieve even the lowest level. Which may be in some sense accurate, but isn't very useful.

We did similar research on Scorecards that we published here; it was doable but a lot of rough edges in documentation and implementation for many solo maintainers: https://blog.tidelift.com/new-data-showing-the-impact-of-paying-maintainers-to-improve-open-source-security

webmink, to random
@webmink@meshed.cloud avatar

Now that Europe is using fake time as well, the window in which Europe-America meetings are at considerate times has once again shrunk.

Loukas,
@Loukas@mastodon.nu avatar

@webmink to paraphrase Thor, all time is fake.

webmink, to random
@webmink@meshed.cloud avatar

So when are we going to get rid of fake time? I thought Europe had it in hand and then ... birdsong.

mansr,
@mansr@society.oftrolls.com avatar

@webmink Something something covid, I think.

webmink, to Redis
@webmink@meshed.cloud avatar

Almost without skipping a beat, the Linux Foundation has forked following the betrayal of its community.
https://www.linuxfoundation.org/press/linux-foundation-launches-open-source-valkey-community

jaschop,
@jaschop@det.social avatar

@webmink
Interesting to see two projects take Redis into two different directions:

  • Valkey with a permissive license and industry support

  • Redict with the LGPL and based on Codeberg

Good showcase of different movements within the OS scene, imo.

webmink, to medical
@webmink@meshed.cloud avatar

With excellent timing given the upcoming request for #standards for #CRA compliance and the forthcoming review of regulation 1025 and standards #policy, CJEU has ruled that "harmonised standards form part of EU law" and cannot be kept secret as there is always a public interest in their disclosure. Time for some modernisation.

Well done once again @carlmalamud and team!
https://curia.europa.eu/juris/document/document.jsf?docid=283443&mode=req&pageIndex=1&dir=&occ=first&part=1&text=&doclang=EN&cid=6387651

webmink, to opensource
@webmink@meshed.cloud avatar

The final version of the is now public and it seems the risks we worried about all last year have been addressed.

Yes, the regulators listened. And they are back at to tell us about it.

https://blog.opensource.org/the-european-regulators-listened-to-the-open-source-communities/

@osi

webmink,
@webmink@meshed.cloud avatar
webmink, to opensource
@webmink@meshed.cloud avatar

The group of FOSS community members who have been engaging the legislators over the CRA are hosting a at . It is an experiment in bringing legislators and community members together to truly hear each other in four two-hour workshops.

You are invited - please join at one of the [begin workshop] points in the schedule. https://fosdem.org/2024/schedule/track/eu-policy/

webmink, to random
@webmink@meshed.cloud avatar

Chutzpah: When RyanAir claims of online booking sites that "many of them overcharge customers with extra fees."

https://www.theguardian.com/business/2024/jan/03/ryanair-ticket-sales-hit-after-travel-agent-websites-delist-airline

samueljohnson,
@samueljohnson@mstdn.social avatar

@hedders @webmink Ryanair is well known for having a v good & humorous social media footprint and to be v adept at getting people talking about it, which is all free (there's no such thing as bad) publicity.

stshank,
@stshank@mstdn.social avatar

@webmink hahahah!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • tacticalgear
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Durango
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ngwrru68w68
  • kavyap
  • GTA5RPClips
  • provamag3
  • ethstaker
  • InstantRegret
  • Leos
  • normalnudes
  • everett
  • khanakhh
  • osvaldo12
  • cisconetworking
  • modclub
  • anitta
  • tester
  • megavids
  • lostlight
  • All magazines