Hello!
In June 2026, Red Hat announced that it has formally identified itself as an Open Source Software Steward for the EU Cyber Resilience Act (CRA), and that the Pulp Project has been selected for the Light Stewardship program.
As most of you might know, the Pulp Project core team is already composed of Red Hat employees, so what has really changed? The answer is that now there is a dedicated support group at Red Hat (cra-steward@redhat.com) whose goal is to help assisted projects meet regulatory criteria for open-source projects.
The CRA stewardship program aims to respect and preserve project community practices, so the biggest change required by them was to improve some of our security policy and practices. As a result, we are now hosting a new Security Policy under the pulp/governance repository, which ought to be the source of truth for this and other project policies and processes.
The new security policy describes things such as the scope of the policies, the vulnerability and incident management processes, and secure development practices. Some of its contents are requirements from the Red Hat CRA team, but some are open to change. We tried to be realistic, but there might be something misleading or missing, so we invite you to read, review, and provide feedback.
This new policy will show up as the standard security policy for all repositories under the Pulp GitHub organization.
Let us know if you have any questions!
Thanks,
Andrew Thomas, Grant Gainey, Matthias Dellweg, Pedro Brochado