Bitsea Logo
  • About us
  • Services
  • Resources
  • Contact
  • Careers
Get_your_M&A_audit
Bitsea Logo

When a FOSS Patch Becomes a Legal Obligation: CRA Vulnerability Handling and the New Responsibility of Integrators

17.04.2026

Dr. Andreas Kotulla

supply chain

The Cyber Resilience Act (CRA) introduces a subtle but profound shift in how manufacturers must think about open source software. For years, integrating free and open-source software (FOSS) into products largely meant relying on upstream maintainers for fixes, monitoring vulnerabilities, and updating when patches became available. Under the CRA, that passive model no longer holds. In certain situations, a vulnerability

Read more

Trivy, KICS, LiteLLM: A Supply Chain Warning on Transitive Dependencies

07.04.2026

Dr. Andreas Kotulla

supply chain

How a compromise in trusted security tooling rippled through Checkmarx KICS and LiteLLM, exposing the real risk of transitive dependencies. The past several days has been a serious reminder that supply chain attacks do not stop with the first compromised project. What started with a malicious Trivy release appears to have widened into a separate but similar attack involving Checkmarx

Read more
  • Privacy Policy
  • Imprint
  • German

Copyright 2026 Bitsea US, Inc.

About us

  • Vision
  • Timeline
  • Tisax
  • Associations
  • Partners
  • Sustainability

Services and Solutions

  • Open Source Management
  • Software Quality Analysis

Resources

  • Research
  • Webinars
  • Blog
  • Events
  • Lexicon
  • Datasheets

Careers

  • Life at Bitsea
  • Jobs

Contact Us

+1-510-593-6757
info@bitsea.us
Request a demo

  • About us
    • About us
    • Vision
    • Timeline
    • Tisax
    • Associations
    • Partners
    • Sustainability
  • Services
    • Services
    • Open Source Management
    • Software Quality Analysis
    • Technical Project Management
  • Resources
    • Resources
    • Research
    • Webinars
    • Events
    • Blog
    • Lexicon
  • Contact
  • Careers
    • Careers
    • Life at Bitsea