Public


Hi OpenAMP TSC,

 

Based on the March 2026 OpenAMP Board meeting, the OpenAMP System Reference working group has been discussing what needs to be done in preparation for the EU Cyber Resilience Act.

 

Conclusions:

 

Votes can be sent directly to me with Arnaud in CC.  The rules for the vote are the same applied for Board voting, described in the charter.  TSC voting members will get a reminder in about a week & voting will close on 17th Sept, 2026.

 

===

Purpose

This policy outlines how security issues in repos of the OpenAMP GitHub organization should be reported, how they are handled, and what users can expect from the OpenAMP Project.

 

Scope

OpenAMP does not ship products or deployable binaries; it supplies source code and reference implementations only. 

 

Because the project team has very limited visibility into how the code is incorporated downstream and very limited maintainer time, consumers of the OpenAMP code are responsible for implementing any security fixes, mitigations, or processes that meet their own regulatory or product-specific requirements.  Organisations placing devices or software on the EU market under the CRA remain accountable for performing their own risk and conformity assessments, generating and maintaining any required SBOMs, and any other EU CRA compliance.

 

Fixes contributed for reported issues will be evaluated and merged on a reasonable-effort basis.  The OpenAMP project welcomes patches that improve CRA alignment, provided they do not impose an unsustainable maintenance burden on the community.

 

Security support is limited to the next release: fixes will be added to the main branch of the relevant repositories.  Earlier versions remain available as-is, but do NOT receive security updates.

 

Response targets 

Acknowledgement, assessment & publishing of advisories will occur on a reasonable-effort basis.  If you need a faster turnaround, please consider contributing a fix or maintaining a downstream fork.

 

Reporting a Vulnerability

If you discover a security vulnerability in OpenAMP, please report it privately and responsibly: open a confidential security issue on at https://github.com/OpenAMP/<repository-with-the-issue>/security/advisories

 

Please include:

 

GitHub How-to documentation on privately reporting a security vulnerability can be found here.

 

To keep this process safe and productive for everyone, all reports and related activities must comply with the OpenAMP Project code of conduct.

 

No Pre-disclosure List

 

Publication of Security Advisories

Advisories will be published at https://github.com/OpenAMP/<repository>/security/advisories.

 

Reported issues that are assessed to be purely theoretical and not applicable in any real hardware system will be documented as “[Fix not planned]”.

 

Limitations of Liability & No Legal Advice

This document is provided “AS IS” and does not constitute legal advice.  The OpenAMP project members make no warranties regarding compliance with any law or regulation.  Use at your own risk.

===

 

Thanks & regards,

Nathalie