From c288432e12cef5f9393594adbd4f0d91fb587146 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Stefan=20B=C3=BCrk?= Date: Thu, 27 Aug 2026 15:43:34 +0200 Subject: [PATCH] [TASK] Add CRA conformity documents Adds the security policy and the EU declaration of conformity for this release branch, taken verbatim from the wv-people/cra repository (main, 18505c5), which is the single source of truth for these documents. SECURITY.md replaces the previous version: the supported versions are a table now and carry an end of support date per major version, derived from the community support end of the highest TYPO3 version that major supports. The README gains the simplified declaration under Annex VI with the exact address of the full declaration, the supported version table, the reporting channel and the license. TER and Packagist build their product pages from the README rather than from SECURITY.md, so that is the only place reaching those channels. --- EU-Declaration-of-Conformity.md | 72 +++++++++++++++++++++++++++++++++ EU-Konformitaetserklaerung.md | 72 +++++++++++++++++++++++++++++++++ README.md | 31 ++++++++++++++ SECURITY.md | 72 +++++++++++++++++++++++++++++++++ 4 files changed, 247 insertions(+) create mode 100644 EU-Declaration-of-Conformity.md create mode 100644 EU-Konformitaetserklaerung.md create mode 100644 SECURITY.md diff --git a/EU-Declaration-of-Conformity.md b/EU-Declaration-of-Conformity.md new file mode 100644 index 0000000..680901e --- /dev/null +++ b/EU-Declaration-of-Conformity.md @@ -0,0 +1,72 @@ +# EU Declaration of Conformity + +**Product:** DeepL Write +**Reference:** DoC-deepl_write-1.1.0 + +## 1. Product identification + +- **Product name:** DeepL Write +- **Type:** TYPO3 Extension +- **Extension key / package:** deepl_write (web-vision/deepl-write) +- **Version:** 1.1.0 (initial issuance of this declaration) +- **Valid for:** version 1.1.0 and subsequent releases, until superseded by a new declaration issued for a later substantial modification (Art. 3(30) CRA) +- **Distribution channels:** TYPO3 Extension Repository (TER) — https://extensions.typo3.org/extension/deepl_write; Packagist — https://packagist.org/packages/web-vision/deepl-write + +## 2. Manufacturer + +web-vision GmbH +An der Eickesmühle 38 +41238 Mönchengladbach +Germany + +## 3. Statement of sole responsibility + +This EU declaration of conformity is issued under the sole responsibility +of the manufacturer, web-vision GmbH. + +## 4. Object of the declaration + +DeepL Write, version 1.1.0, as distributed via the TYPO3 Extension +Repository (TER) and Packagist. + +## 5. Statement of conformity + +The object of the declaration described above is in conformity with +Regulation (EU) 2024/2847 (Cyber Resilience Act). No other Union +harmonisation legislation is applicable. + +## 6. Standards, specifications, certification + +No harmonised standards applied; conformity assessed under Module A +(internal control), see Section 7. + +## 7. Conformity assessment procedure + +- **Risk class (see CRA-Risikoklassen.md):** Standard +- **Conformity assessment module (see Annex VIII CRA):** Module A – internal control +- **Notified body name and number:** N/A — self-assessed under Module A, no notified body involved +- **Certificate identification:** N/A — see above + +## 8. Signature + +Signed for and on behalf of: web-vision GmbH + +- **Place and date of issue:** Mönchengladbach, 27 August 2026 +- **Name, function:** Stefan Bürk, CISO, i.A. der Geschäftsführung (VOLLMACHT-CISO-2026-01) +- **Signature:** Stefan Bürk + +--- + +## Simplified EU Declaration of Conformity (Annex VI) + +> Hereby, web-vision GmbH declares that the product with digital elements +> type DeepL Write is in compliance with Regulation (EU) 2024/2847. +> +> The full text of the EU declaration of conformity is available at the +> following internet address: +> https://security.web-vision.de/conformity/web-vision/deepl-write/1.1.0/en/ + +## References + +- TEMPLATE-EU-Declaration-of-Conformity.md +- Vollmacht-Konformitaetserklaerung.md (VOLLMACHT-CISO-2026-01) diff --git a/EU-Konformitaetserklaerung.md b/EU-Konformitaetserklaerung.md new file mode 100644 index 0000000..d09da45 --- /dev/null +++ b/EU-Konformitaetserklaerung.md @@ -0,0 +1,72 @@ +# EU-Konformitätserklärung + +**Produkt:** DeepL Write +**Referenz:** DoC-deepl_write-1.1.0 + +## 1. Produktidentifikation + +- **Produktname:** DeepL Write +- **Typ:** TYPO3-Extension +- **Extension Key / Package:** deepl_write (web-vision/deepl-write) +- **Version:** 1.1.0 (Erstausstellung dieser Erklärung) +- **Gültig für:** Version 1.1.0 und nachfolgende Releases, bis eine neue Erklärung wegen einer späteren wesentlichen Änderung (Art. 3 Nr. 30 CRA) ausgestellt wird +- **Vertriebskanäle:** TYPO3 Extension Repository (TER) — https://extensions.typo3.org/extension/deepl_write; Packagist — https://packagist.org/packages/web-vision/deepl-write + +## 2. Hersteller + +web-vision GmbH +An der Eickesmühle 38 +41238 Mönchengladbach +Deutschland + +## 3. Erklärung der alleinigen Verantwortung + +Die alleinige Verantwortung für die Ausstellung dieser +EU-Konformitätserklärung trägt der Hersteller, web-vision GmbH. + +## 4. Gegenstand der Erklärung + +DeepL Write, Version 1.1.0, vertrieben über das TYPO3 Extension +Repository (TER) und Packagist. + +## 5. Konformitätserklärung + +Der oben beschriebene Gegenstand der Erklärung erfüllt die Vorgaben der +Verordnung (EU) 2024/2847 (Cyber Resilience Act). Weitere +Harmonisierungsrechtsvorschriften der Union sind nicht anwendbar. + +## 6. Normen, Spezifikationen, Zertifizierung + +Keine harmonisierten Normen angewandt; Konformität nach Modul A (interne +Kontrolle) bewertet, siehe Abschnitt 7. + +## 7. Konformitätsbewertungsverfahren + +- **Risikoklasse (siehe CRA-Risikoklassen.md):** Standard +- **Konformitätsbewertungsmodul (siehe Anhang VIII CRA):** Modul A – interne Kontrolle +- **Name und Nummer der notifizierten Stelle:** Entfällt — Selbstbewertung nach Modul A, keine notifizierte Stelle beteiligt +- **Kennnummer des Zertifikats:** Entfällt — siehe oben + +## 8. Unterschrift + +Unterzeichnet für und im Namen von: web-vision GmbH + +- **Ort und Datum der Ausstellung:** Mönchengladbach, 27.08.2026 +- **Name, Funktion:** Stefan Bürk, CISO, i.A. der Geschäftsführung (VOLLMACHT-CISO-2026-01) +- **Unterschrift:** Stefan Bürk + +--- + +## Vereinfachte EU-Konformitätserklärung (Anhang VI) + +> Hiermit erklärt die web-vision GmbH, dass das Produkt mit digitalen +> Elementen des Typs DeepL Write der Verordnung (EU) 2024/2847 entspricht. +> +> Der vollständige Text der EU-Konformitätserklärung ist unter der +> folgenden Internetadresse verfügbar: +> https://security.web-vision.de/conformity/web-vision/deepl-write/1.1.0/de/ + +## Referenzen + +- TEMPLATE-EU-Konformitaetserklaerung.md +- Vollmacht-Konformitaetserklaerung.md (VOLLMACHT-CISO-2026-01) diff --git a/README.md b/README.md index 0310c89..42a17a7 100644 --- a/README.md +++ b/README.md @@ -115,3 +115,34 @@ echo '>> Create release based on configuration' ; \ gh pr merge -rd --admin && \ git remote prune origin ``` + +## Supported Versions + +| Version | Supported | End of Support | +|---------|--------------------|----------------| +| 2.x | :white_check_mark: | 2029-06-30 | +| 1.x | :white_check_mark: | 2027-12-31 | + +## Security + +Found a vulnerability? Please report it privately via our +[security report form](https://security.web-vision.de) — **do not** open a public issue. +See [SECURITY.md](SECURITY.md) for the full vulnerability disclosure policy, +including what to expect and our safe harbor statement. + +## Simplified EU Declaration of Conformity (Annex VI) + +> Hereby, web-vision GmbH declares that the product with digital elements +> type DeepL Write is in compliance with Regulation (EU) 2024/2847. +> +> The full text of the EU declaration of conformity is available at the +> following internet address: +> https://security.web-vision.de/conformity/web-vision/deepl-write/1.1.0/en/ + +The full declarations are also included in this repository: +[English](EU-Declaration-of-Conformity.md) · +[Deutsch](EU-Konformitaetserklaerung.md). + +## License + +This extension is released under the [GPL-2.0-or-later](LICENSE) license. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..05831da --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,72 @@ +# Security Policy + +This product ("web-vision/deepl-write") is developed and maintained by web-vision GmbH. +As a manufacturer of a product with digital elements under the EU Cyber +Resilience Act (Regulation (EU) 2024/2847), we are committed to identifying, +assessing, and remediating security vulnerabilities in this product in a +timely manner, and to coordinating responsibly with security researchers. + +## Supported Versions + +Security updates are provided for the following versions. Versions marked +unsupported no longer receive security fixes; please upgrade before +reporting an issue against them. + +| Version | Supported | End of Support | +|---------|--------------------|----------------| +| 2.x | :white_check_mark: | 2029-06-30 | +| 1.x | :white_check_mark: | 2027-12-31 | + +## Reporting a Vulnerability + +Please report suspected security vulnerabilities privately — **do not** +open a public GitHub/GitLab issue. + +- **Report here:** https://security.web-vision.de (our secure incident report form) +- **Please include:** affected version(s), a description of the issue, + steps to reproduce or a proof of concept, and the potential impact. + +### What to expect + +| Step | Timeframe | +|-------------------------------------|------------------------------------------------------------------------| +| Acknowledgement of your report | within 1 business day (typically much faster) | +| Status updates | at least every 7 days until resolved | +| Fix / mitigation, based on severity | Critical/High: as fast as possible; Medium/Low: next scheduled release | + +We coordinate the disclosure timeline with the reporter and aim for a +resolution before any public disclosure. If you'd like credit for your +finding, let us know how you'd like to be named; we're also happy to keep +your report confidential if you prefer. + +## Safe Harbor + +We consider security research conducted in good faith, in accordance with +this policy, to be authorized. We will not pursue legal action against +researchers who: + +- make a genuine effort to avoid privacy violations, data destruction, and + service interruption during their research, +- report a vulnerability promptly and do not exploit it beyond what is + necessary to demonstrate the issue, +- do not publicly disclose the vulnerability before we have had a + reasonable opportunity to address it (see timeframes above). + +## Scope + +In scope: the source code, released versions, and the official distribution +channels of "web-vision/deepl-write": + +- TYPO3 Extension Repository (TER) — https://extensions.typo3.org/extension/deepl_write +- Packagist — https://packagist.org/packages/web-vision/deepl-write + +Out of scope: third-party dependencies (please report those upstream, but +feel free to let us know so we can track and update them), and +vulnerabilities in the host application (TYPO3 core) itself +unless directly caused by this extension. + +## Coordinator + +Vulnerability reports for this product are handled by the +Vulnerability Coordinator team at web-vision GmbH, +under the oversight of our GRC/CISO function.