
CRA vulnerability reporting with Daniel Thompson
Show notes
Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it's not too bad. There are plenty more requirements coming, but this one feels very approachable.
The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-09-daniel-cra