From de721f725d6ded0144f3fd8e4eeea153fd7b7470 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Stefan=20B=C3=BCrk?= Date: Thu, 27 Aug 2026 15:43:22 +0200 Subject: [PATCH] [TASK] Add CRA conformity documents Adds the security policy and the EU declaration of conformity for this release branch, taken verbatim from the wv-people/cra repository (main, 18505c5), which is the single source of truth for these documents. SECURITY.md replaces the previous version: the supported versions are a table now and carry an end of support date per major version, derived from the community support end of the highest TYPO3 version that major supports. The README gains the simplified declaration under Annex VI with the exact address of the full declaration, the supported version table, the reporting channel and the license. TER and Packagist build their product pages from the README rather than from SECURITY.md, so that is the only place reaching those channels. --- EU-Declaration-of-Conformity.md | 72 +++++++++++++++++++++++++++++++++ EU-Konformitaetserklaerung.md | 72 +++++++++++++++++++++++++++++++++ README.md | 31 ++++++++++++++ SECURITY.md | 20 ++++----- 4 files changed, 185 insertions(+), 10 deletions(-) create mode 100644 EU-Declaration-of-Conformity.md create mode 100644 EU-Konformitaetserklaerung.md diff --git a/EU-Declaration-of-Conformity.md b/EU-Declaration-of-Conformity.md new file mode 100644 index 0000000..1da1e01 --- /dev/null +++ b/EU-Declaration-of-Conformity.md @@ -0,0 +1,72 @@ +# EU Declaration of Conformity + +**Product:** DeepL Write +**Reference:** DoC-deepl_write-2.1.0 + +## 1. Product identification + +- **Product name:** DeepL Write +- **Type:** TYPO3 Extension +- **Extension key / package:** deepl_write (web-vision/deepl-write) +- **Version:** 2.1.0 (initial issuance of this declaration) +- **Valid for:** version 2.1.0 and subsequent releases, until superseded by a new declaration issued for a later substantial modification (Art. 3(30) CRA) +- **Distribution channels:** TYPO3 Extension Repository (TER) — https://extensions.typo3.org/extension/deepl_write; Packagist — https://packagist.org/packages/web-vision/deepl-write + +## 2. Manufacturer + +web-vision GmbH +An der Eickesmühle 38 +41238 Mönchengladbach +Germany + +## 3. Statement of sole responsibility + +This EU declaration of conformity is issued under the sole responsibility +of the manufacturer, web-vision GmbH. + +## 4. Object of the declaration + +DeepL Write, version 2.1.0, as distributed via the TYPO3 Extension +Repository (TER) and Packagist. + +## 5. Statement of conformity + +The object of the declaration described above is in conformity with +Regulation (EU) 2024/2847 (Cyber Resilience Act). No other Union +harmonisation legislation is applicable. + +## 6. Standards, specifications, certification + +No harmonised standards applied; conformity assessed under Module A +(internal control), see Section 7. + +## 7. Conformity assessment procedure + +- **Risk class (see CRA-Risikoklassen.md):** Standard +- **Conformity assessment module (see Annex VIII CRA):** Module A – internal control +- **Notified body name and number:** N/A — self-assessed under Module A, no notified body involved +- **Certificate identification:** N/A — see above + +## 8. Signature + +Signed for and on behalf of: web-vision GmbH + +- **Place and date of issue:** Mönchengladbach, 27 August 2026 +- **Name, function:** Stefan Bürk, CISO, i.A. der Geschäftsführung (VOLLMACHT-CISO-2026-01) +- **Signature:** Stefan Bürk + +--- + +## Simplified EU Declaration of Conformity (Annex VI) + +> Hereby, web-vision GmbH declares that the product with digital elements +> type DeepL Write is in compliance with Regulation (EU) 2024/2847. +> +> The full text of the EU declaration of conformity is available at the +> following internet address: +> https://security.web-vision.de/conformity/web-vision/deepl-write/2.1.0/en/ + +## References + +- TEMPLATE-EU-Declaration-of-Conformity.md +- Vollmacht-Konformitaetserklaerung.md (VOLLMACHT-CISO-2026-01) diff --git a/EU-Konformitaetserklaerung.md b/EU-Konformitaetserklaerung.md new file mode 100644 index 0000000..045b01d --- /dev/null +++ b/EU-Konformitaetserklaerung.md @@ -0,0 +1,72 @@ +# EU-Konformitätserklärung + +**Produkt:** DeepL Write +**Referenz:** DoC-deepl_write-2.1.0 + +## 1. Produktidentifikation + +- **Produktname:** DeepL Write +- **Typ:** TYPO3-Extension +- **Extension Key / Package:** deepl_write (web-vision/deepl-write) +- **Version:** 2.1.0 (Erstausstellung dieser Erklärung) +- **Gültig für:** Version 2.1.0 und nachfolgende Releases, bis eine neue Erklärung wegen einer späteren wesentlichen Änderung (Art. 3 Nr. 30 CRA) ausgestellt wird +- **Vertriebskanäle:** TYPO3 Extension Repository (TER) — https://extensions.typo3.org/extension/deepl_write; Packagist — https://packagist.org/packages/web-vision/deepl-write + +## 2. Hersteller + +web-vision GmbH +An der Eickesmühle 38 +41238 Mönchengladbach +Deutschland + +## 3. Erklärung der alleinigen Verantwortung + +Die alleinige Verantwortung für die Ausstellung dieser +EU-Konformitätserklärung trägt der Hersteller, web-vision GmbH. + +## 4. Gegenstand der Erklärung + +DeepL Write, Version 2.1.0, vertrieben über das TYPO3 Extension +Repository (TER) und Packagist. + +## 5. Konformitätserklärung + +Der oben beschriebene Gegenstand der Erklärung erfüllt die Vorgaben der +Verordnung (EU) 2024/2847 (Cyber Resilience Act). Weitere +Harmonisierungsrechtsvorschriften der Union sind nicht anwendbar. + +## 6. Normen, Spezifikationen, Zertifizierung + +Keine harmonisierten Normen angewandt; Konformität nach Modul A (interne +Kontrolle) bewertet, siehe Abschnitt 7. + +## 7. Konformitätsbewertungsverfahren + +- **Risikoklasse (siehe CRA-Risikoklassen.md):** Standard +- **Konformitätsbewertungsmodul (siehe Anhang VIII CRA):** Modul A – interne Kontrolle +- **Name und Nummer der notifizierten Stelle:** Entfällt — Selbstbewertung nach Modul A, keine notifizierte Stelle beteiligt +- **Kennnummer des Zertifikats:** Entfällt — siehe oben + +## 8. Unterschrift + +Unterzeichnet für und im Namen von: web-vision GmbH + +- **Ort und Datum der Ausstellung:** Mönchengladbach, 27.08.2026 +- **Name, Funktion:** Stefan Bürk, CISO, i.A. der Geschäftsführung (VOLLMACHT-CISO-2026-01) +- **Unterschrift:** Stefan Bürk + +--- + +## Vereinfachte EU-Konformitätserklärung (Anhang VI) + +> Hiermit erklärt die web-vision GmbH, dass das Produkt mit digitalen +> Elementen des Typs DeepL Write der Verordnung (EU) 2024/2847 entspricht. +> +> Der vollständige Text der EU-Konformitätserklärung ist unter der +> folgenden Internetadresse verfügbar: +> https://security.web-vision.de/conformity/web-vision/deepl-write/2.1.0/de/ + +## Referenzen + +- TEMPLATE-EU-Konformitaetserklaerung.md +- Vollmacht-Konformitaetserklaerung.md (VOLLMACHT-CISO-2026-01) diff --git a/README.md b/README.md index e9836d6..eb8c4d7 100644 --- a/README.md +++ b/README.md @@ -137,3 +137,34 @@ echo '>> Create release based on configuration' ; \ gh pr merge -rd --admin && \ git remote prune origin ``` + +## Supported Versions + +| Version | Supported | End of Support | +|---------|--------------------|----------------| +| 2.x | :white_check_mark: | 2029-06-30 | +| 1.x | :white_check_mark: | 2027-12-31 | + +## Security + +Found a vulnerability? Please report it privately via our +[security report form](https://security.web-vision.de) — **do not** open a public issue. +See [SECURITY.md](SECURITY.md) for the full vulnerability disclosure policy, +including what to expect and our safe harbor statement. + +## Simplified EU Declaration of Conformity (Annex VI) + +> Hereby, web-vision GmbH declares that the product with digital elements +> type DeepL Write is in compliance with Regulation (EU) 2024/2847. +> +> The full text of the EU declaration of conformity is available at the +> following internet address: +> https://security.web-vision.de/conformity/web-vision/deepl-write/2.1.0/en/ + +The full declarations are also included in this repository: +[English](EU-Declaration-of-Conformity.md) · +[Deutsch](EU-Konformitaetserklaerung.md). + +## License + +This extension is released under the [GPL-2.0-or-later](LICENSE) license. diff --git a/SECURITY.md b/SECURITY.md index 35d03fc..05831da 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -12,13 +12,10 @@ Security updates are provided for the following versions. Versions marked unsupported no longer receive security fixes; please upgrade before reporting an issue against them. -| Version | Supported | -| ------- | ------------------ | -| 2.x | :white_check_mark: | -| 1.x | :white_check_mark: | -| < 1.0 | :x: | - -Planned end of support for this product: **30 June 2029 (end of regular TYPO3 14 LTS support)**. +| Version | Supported | End of Support | +|---------|--------------------|----------------| +| 2.x | :white_check_mark: | 2029-06-30 | +| 1.x | :white_check_mark: | 2027-12-31 | ## Reporting a Vulnerability @@ -32,7 +29,7 @@ open a public GitHub/GitLab issue. ### What to expect | Step | Timeframe | -| ----------------------------------- | ---------------------------------------------------------------------- | +|-------------------------------------|------------------------------------------------------------------------| | Acknowledgement of your report | within 1 business day (typically much faster) | | Status updates | at least every 7 days until resolved | | Fix / mitigation, based on severity | Critical/High: as fast as possible; Medium/Low: next scheduled release | @@ -57,8 +54,11 @@ researchers who: ## Scope -In scope: the source code, released versions, and official distribution -channels of "web-vision/deepl-write" (e.g. TER / Packagist). +In scope: the source code, released versions, and the official distribution +channels of "web-vision/deepl-write": + +- TYPO3 Extension Repository (TER) — https://extensions.typo3.org/extension/deepl_write +- Packagist — https://packagist.org/packages/web-vision/deepl-write Out of scope: third-party dependencies (please report those upstream, but feel free to let us know so we can track and update them), and