{"id":12029,"date":"2023-03-29T15:49:00","date_gmt":"2023-03-29T13:49:00","guid":{"rendered":"http:\/\/plus.maciejpiasecki.info\/index.php\/2023\/03\/29\/why-the-european-commission-must-consult-the-open-source-communities\/"},"modified":"2023-03-29T23:57:30","modified_gmt":"2023-03-29T21:57:30","slug":"why-the-european-commission-must-consult-the-open-source-communities","status":"publish","type":"post","link":"https:\/\/plus.maciejpiasecki.info\/index.php\/2023\/03\/29\/why-the-european-commission-must-consult-the-open-source-communities\/","title":{"rendered":"Why the European Commission must consult the Open Source communities"},"content":{"rendered":"<p>A crucial problem with the Impact Assessment of the Cyber Resilience Act (CRA) is that no Open Source communities or community fiduciaries were consulted as stakeholders. The lack of consultation with the Open Source communities would explain the possible origin of a serious defect in terminology.<br \/>\nThe Impact Assessment Annex 2 (Pdf), sections 2-4 lists the consulted stakeholders and Open Source communities aren\u2019t there. During a FOSDEM Main Stage panel, the European Commission\u2019s policy officers explained they had been working on the language of the updates to the Public Liability Directive (PLD) and CRA for a significant time. When asked why they had not consulted the community until now (at 1:27:45 on the video), they replied it was the community\u2019s responsibility to find out about their work and show up to published consultations.<br \/>\nIt is not enough to expect the Open Source ecosystem\u00a0to spontaneously show up \u2013 it is not structured\u00a0in a way that makes that likely. In any case, the consultation process\u00a0has no category\u00a0for individuals who make economically significant works outside the role of \u201cCompany\u201d or \u201cWorkforce.\u201d In other words, there were\u00a0no consultations aimed at the community. At best we will show up late in the process asking why no-one called, as we are now.<br \/>\nIt is not unreasonable to ask to be treated in a way respectful of these realities; the process does so for SMEs. Section 4 of Annex 2 observes \u201cHowever, it has been very difficult to get substantial input from SMEs.\u201d As a result, there was extensive, targeted outreach to SMEs resulting in significant inputs. No equivalent effort was made to reach out to Open Source charities like OSI, or to significant fiduciaries like Apache, Eclipse or Python.<br \/>\nIt\u2019s great that companies in the Open Source ecosystem do show up in consultations, and I know of a number who have lobbyists in Brussels. But they cannot be relied upon to explain or even consider the perspectives of the significant number of community participants either outside their interest area or even opposed to it.<br \/>\nIt is very important to find ways to give a voice to the true community and not just its corporate members. Open Source is a social movement with software artifacts and market consequences. Paying heed only to the latter (or even the latter two) is an inadequate approach. You can\u2019t proxy through SMEs, let alone multinationals and their lobbyists.<br \/>\nThis is a serious and persistent issue with the Commission\u2019s work; they need to become aware that when proposals affect the Open Source ecosystem (of which the Open Source software market they value is a part, but not the whole), it is essential\u00a0for them to treat the\u00a0members of that ecosystem\u00a0as key stakeholders and make at least as much of an effort to reach out to them as they do to SMEs \u2014 possibly more.&#013;<br \/>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/plus.maciejpiasecki.info\/wp-content\/uploads\/2023\/03\/7IwVHTPo7RluA8WraxvIoac6RwsBXZy1lArh9Xyd-1024x771-1.jpg\" width=\"1024\" height=\"771\">&#013;<br \/>\nSource: opensource.org&#013;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A crucial problem with the Impact Assessment of the Cyber Resilience Act (CRA) is that no Open Source communities or [&hellip;]<\/p>\n","protected":false},"author":48,"featured_media":12030,"comment_status":"false","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-12029","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mp"],"_links":{"self":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/12029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/users\/48"}],"replies":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/comments?post=12029"}],"version-history":[{"count":1,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/12029\/revisions"}],"predecessor-version":[{"id":12031,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/12029\/revisions\/12031"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/media\/12030"}],"wp:attachment":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/media?parent=12029"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/categories?post=12029"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/tags?post=12029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}