The EU Cyber Resilience Act (CRA), with most obligations kicking in around 2027, is creating an unexpected incentive for companies to donate internal tools to open source foundations like the Linux Foundation, CNCF, or Apache. By transferring ownership to a foundation, companies shift from owning a 'commercial product with
Table of contents
What the CRA actually doesThe foundation strategyCould this actually be good for open source?What the CRA might actually changeSort: