From nobody Mon Jul 20 12:00:02 2026 X-Original-To: dev-commits-doc-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4h3fGC0Gyxz6lrKk for ; Mon, 20 Jul 2026 12:00:03 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4h3fGB4T9sz3M2q for ; Mon, 20 Jul 2026 12:00:02 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1784548802; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=LUmsjd+RLrbRNwZVnA2TLkJmbJ3hc4xhs+v59iuIAdg=; b=X3WvaIubHoG6R+l5o9mdHXAsxKp3DLiD4c4WV6bXWfL0dwJyHtm4VzzeVv8GutUnZJWyHb ZMeg8EdzXpH73yW7SRxInP+zVxQXxK/n3cfQ5YTpP390S4TH//UqRrQLJQsZ9Q5ccQeo4v DpNUxm0zQn811FUSd+N7QQ9whinsOa4nKQu+u3ieVyE+TPN4hZ5pH+xtB6xOcE3Ddof80e uNUmerAPUOVFzfHTMok2uA71EEMpvZdgFKdrCKuAx1KFh16MOmQNGbuuGB+OJyTZAyAlU1 fGwC8Yk21kexpvplWm0kUBvke8CtBrjhpvzgUA1XzD5tjayNBCktv0p9ElWYMQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1784548802; a=rsa-sha256; cv=none; b=HfgRESQIkuBvybfANNEW36qOSNvJay7hy7sPDDZqR0hTv2+lWrsWuwJMfJD69pVg8TxL07 J6dRn4H0hVxRyt8dqnP2MSbvYrm7+cNu8hfwb0aDPdbmebd/mI/1fSfvEGw2yq2kD66gBk J0HyATTQJMBVdpujzzfVC7LzDIW7+JDbYtsVunwek7IX5zmwY5K6t52yd/Y8Xi0G/2tbh7 j/6xhF1bgxGhx5K55/ceo8h2+rAtFlI8paNvwGi9PsNun1AQN/g0cg7Rt1oynAXBKWAQhx ePM3zW304C2sKXumClAqOp6fW9a0+VQqGkIqsLtPGriGmQ68U0zw+dgHULYnug== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1784548802; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=LUmsjd+RLrbRNwZVnA2TLkJmbJ3hc4xhs+v59iuIAdg=; b=HSFAXZUPvokBAIMWZD2WK2wddP2Yz6kZ1IXcppE+gjXT7jJJ0EJ+Ks2yTIMgYPC6Fwru8l od/u7pArhgIHDvEBnFJX9MKfiXfxutxv0ilLpMXK5yQbZ3luxx+yaDPVnAKvhgEys2mA3b 49I3JUooXx0b1/bt9y3040V+j5Q2r2MNEueOQn0oe24vwdjfBT+ibgTwq/qw8pHJH5+sfo jkKxLyp3/X40njacrseyASYVp2YrU8V6naxVMy3DvSZ6kCDstBrAcDf3D6auozWPjB27xw WPtpoaXa+ddyJ/eGnGuho0gXKN+Wa5+IEh6PkcYJkAOn0mqwqDhQCU96Qlr5QA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4h3fGB3R3vz11Bc for ; Mon, 20 Jul 2026 12:00:02 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3ce7c by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 20 Jul 2026 12:00:02 +0000 To: doc-committers@FreeBSD.org, dev-commits-doc-all@FreeBSD.org Cc: Pierre Pronchery From: Lorenzo Salvadore Subject: git: 488edce7c9 - main - Status/2026Q2: add report List-Id: Commit messages for all branches of the doc repository List-Archive: https://lists.freebsd.org/archives/dev-commits-doc-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-doc-all@freebsd.org Sender: owner-dev-commits-doc-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: salvadore X-Git-Repository: doc X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 488edce7c9a5d156146bcaf645823655b09efc7e Auto-Submitted: auto-generated Date: Mon, 20 Jul 2026 12:00:02 +0000 Message-Id: <6a5e0dc2.3ce7c.4203dec1@gitrepo.freebsd.org> The branch main has been updated by salvadore: URL: https://cgit.FreeBSD.org/doc/commit/?id=488edce7c9a5d156146bcaf645823655b09efc7e commit 488edce7c9a5d156146bcaf645823655b09efc7e Author: Pierre Pronchery AuthorDate: 2026-07-06 07:03:44 +0000 Commit: Lorenzo Salvadore CommitDate: 2026-07-20 11:59:32 +0000 Status/2026Q2: add report This is titled "FreeBSD, CRA, EuroBSDCon, and Security Team". Sponsored by: The FreeBSD Foundation Pull Request: https://github.com/freebsd/freebsd-doc/pull/691 --- .../freebsd-cra-eurobsdcon-and-security-team.adoc | 30 ++++++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/website/content/en/status/report-2026-04-2026-06/freebsd-cra-eurobsdcon-and-security-team.adoc b/website/content/en/status/report-2026-04-2026-06/freebsd-cra-eurobsdcon-and-security-team.adoc new file mode 100644 index 0000000000..a0a4df599e --- /dev/null +++ b/website/content/en/status/report-2026-04-2026-06/freebsd-cra-eurobsdcon-and-security-team.adoc @@ -0,0 +1,30 @@ +=== FreeBSD, CRA, EuroBSDCon, and Security Team + +Links: + +link:https://alpha-omega.dev[Alpha-Omega -- Linux Foundation Project] URL: link:https://alpha-omega.dev[] + +link:https://freebsdfoundation.org[FreeBSD Foundation] URL: link:https://freebsdfoundation.org[] + +link:https://www.freebsd.org/security/[FreeBSD Security Information] URL: link:https://www.freebsd.org/security/[] + +link:https://2026.eurobsdcon.org[EuroBSDCon 2026] URL: link:https://2026.eurobsdcon.org[] + +Contact: Pierre Pronchery + +This quarter marked the beginning of my participation to Alpha-Omega's new initiative around AI. +The new wave of LLM-assisted disclosures of security vulnerabilities has been hard to miss, and Alpha-Omega is now assisting prominent Open Source ecosystems facing this challenge. +This includes FreeBSD, and given the situation, I have volunteered and been accepted into FreeBSD's security team. +My objective there, besides helping with incoming reports where I can, is to understand existing processes and suggest improvements to facilitate and scale operations. +This started with a new instance of link:https://requesttracker.com/rtir/[RTIR], and with an experimental instance of link:https://forgejo.org[Forgejo] for CI/CD and possible leveraging of LLM integration with the security team's workflow. + +On a related note, and in an effort to facilitate compliance with the European link:https://en.wikipedia.org/wiki/Cyber_Resilience_Act[Cyber Resilience Act] (CRA), link:http://pkgconf.org[pkgconf] was imported at version 2.9.93 in FreeBSD's base system. +This now includes man:spdxtool[1], which supports the generation of link:https://en.wikipedia.org/wiki/Software_supply_chain[Software Bill of Material] (SBOM) conforming to link:https://spdx.github.io/spdx-spec/v3.0.1/[SPDX 3.0.1 specification]. +Together with Tuukka Pasanen, we are offering a framework for review to that effect in link:https://reviews.freebsd.org/D56474[D56474], which still requires polishing before import unfortunately. + +First, it should be updated to reflect the availability of spdxtool (a patch is already available). +More importantly, finding the correct granularity for the amount of SBOM files to generate while fitting FreeBSD's build system was not easy. +This explains the metadata still missing in some cases; we are working on it for an approach as consistent as possible from the start. +Lastly, I apologize in advance for the 1.000+ files added to the coming release; hopefully, this will be mitigated by the switch to pkgbase, with which we believe it will fit perfectly. +The SBOM files are expected to be automatically provided in the corresponding packages installed, allowing subsequent SBOM tooling to function with the exact knowledge of the system's status as installed. + +In this context, I am glad to announce that Alice Sowerby, Peter Hansteen, and myself are teaming up to host a workshop about CRA compliance for BSD-based systems during the coming EuroBSDCon conference in Brussels, this September 2026. +You are welcome to join us there for practical information about CRA compliance in our ecosystem! + +Sponsor: Alpha-Omega, The FreeBSD Foundation