Hello FOSSA maintainers,
We are reaching out around the OpenChain CRA Compliance Requirements & Checklist.
We would like to cross-reference relevant CRA, SBOM, SCA, and open source compliance resources so users can find community material that helps with CRA evidence planning. Given FOSSA CLI's role in dependency analysis, license compliance, vulnerability scanning, and SBOM-oriented workflows, would you be open to referencing the OpenChain CRA checklist from the relevant README or documentation, where it fits?
OpenChain CRA checklist:
https://github.com/OpenChain-Project/CRA-Compliance
Annex D external references/adoption section:
https://github.com/OpenChain-Project/CRA-Compliance/blob/main/ANNEX_D_EXTERNAL_REFERENCES_AND_ADOPTION.md
This is only a cross-reference request, not a legal endorsement or conformity assessment claim. If GitHub is not the right place for this, please point us to the best channel.
Thank you.
Hello FOSSA maintainers,
We are reaching out around the OpenChain CRA Compliance Requirements & Checklist.
We would like to cross-reference relevant CRA, SBOM, SCA, and open source compliance resources so users can find community material that helps with CRA evidence planning. Given FOSSA CLI's role in dependency analysis, license compliance, vulnerability scanning, and SBOM-oriented workflows, would you be open to referencing the OpenChain CRA checklist from the relevant README or documentation, where it fits?
OpenChain CRA checklist:
https://github.com/OpenChain-Project/CRA-Compliance
Annex D external references/adoption section:
https://github.com/OpenChain-Project/CRA-Compliance/blob/main/ANNEX_D_EXTERNAL_REFERENCES_AND_ADOPTION.md
This is only a cross-reference request, not a legal endorsement or conformity assessment claim. If GitHub is not the right place for this, please point us to the best channel.
Thank you.