[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Call for vote: public statement about the EU Legislation "Cyber Resilience Act and Product Liability Directive"





On Wed, 15 Nov 2023 at 12:14, Simon Richter <sjr@debian.org> wrote:
Hi,

On 11/15/23 15:22, Lucas Nussbaum wrote:

>>      The Debian project however notes that not enough emphasis has been
>>      employed in all parts of these regulations to clearly exonerate Free
>>      and Open Source Software Projects from being subject to the same
>>      liabilities as commercial products

> I find this part a bit ambiguous. When GitLab or Proxmox or RedHat sells
> services around a free software product, I think it's OK if they are
> covered by this regulation. Maybe it would be better with
> s/Projects/Organizations/?

That is exactly why I think this is dangerous: I want GitLab and Proxmox
to be responsible for what they release, but it is very difficult to
draw a line between their offering and what Microsoft is doing by paying
for systemd development while they are also selling Azure cloud.

Why should there be a borderline between that? Microsoft has to be responsible 
for what they are selling in the Azure cloud (pre-defined images), regardless of
the systemd developer work.

--
Best regards,
    Aigars Mahinovs

Reply to: