Is NixOS ready for the CRA? (nixcon2025) episode artwork

EPISODE · Sep 5, 2025 · 25 MIN

Is NixOS ready for the CRA? (nixcon2025)

from Chaos Computer Club - recent events feed (high quality) · host Lukas Beierlieb

The Cyber Resilience Act (CRA) is the EU's most important regulation for software in the last decade. While it makes an exception for open-source software and impact NixOS directly, any commercial product that includes NixOS has to comply with the CRA to allow offering in the EU. In this talk, we give insights into the CRA’s requirements, showcase that Nix tooling with its focus on reproducibility is very well positioned for compliance, and point out the unsolved shortcomings. We focus on the update mechanism, SBOM tooling (together with matching CVEs from vulnerability mechanisms), and support durations. about this event: https://talks.nixcon.org/nixcon-2025/talk/3XBNPB/

Episode metadata supplied by the publisher feed · Published Sep 5, 2025

Embed this episode

NOW PLAYING

Is NixOS ready for the CRA? (nixcon2025)

0:00 25:27

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - recent events feed (high quality)?

This episode is 25 minutes long.

When was this Chaos Computer Club - recent events feed (high quality) episode published?

This episode was published on September 5, 2025.

Can I download this Chaos Computer Club - recent events feed (high quality) episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!