Skip to content

CRA: complete the Annex II README sections #28

Description

@sbuerk

The CRA pull request that added SECURITY.md, the EU declaration of conformity
and the first README sections was deliberately scoped as phase 1. It covers the
sections that can be generated identically for every extension.

The remaining user-information sections required by Annex II of Regulation
(EU) 2024/2847 need wording specific to this product. The template to follow is
docs/TEMPLATE-README-EN.md in the wv-people/cra repository, which annotates
every section with its Annex II point and states that a section must not be
dropped merely because it is short.

Still to add to README.md:

  • Manufacturer (Annex II pt 1) — legal name, postal address, contact
    address, website. web-vision GmbH, An der Eickesmühle 38, 41238
    Mönchengladbach, Germany.
  • Security environment & security properties (pt 4.2) — mandatory even
    if short.
  • Known risks & foreseeable misuse (pt 5) — if the risk is low, say so
    and justify it briefly rather than omitting the section.
  • Installation & secure initial setup (pt 8.1)
  • Configuration changes & data security (pt 8.2)
  • Installing security updates (pt 8.3)
  • Uninstallation & data removal (pt 8.4)
  • Automatic security updates (pt 8.5)
  • Notes for integrators (pt 8.6)
  • Software Bill of Materials (SBOM) (pt 9)

Points 8.3 to 8.6 and 9 are close to identical across TYPO3 extensions and can
be taken almost verbatim from the template. Points 4.2, 5, 8.1 and 8.2 describe
what this specific extension does and need to be written per product.

Do this on every actively maintained release branch, not only the default one.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions