githubnext / githubnext/gh-aw-cao

[eu-cra-compliance:article-14-reporting-readiness] github/gh-aw-firewall CRA Article 14 readiness

Closed
#12,167 0 comments 0 reactions 0 assignees View on GitHub
eu-cra-compliance eu-cra-compliance:article-14-reporting-readiness
Dominant language
JavaScript
Stars
3
Forks
1
Avg merge
49m
Merged PRs (30d)
837

Description

github/gh-aw-firewall has some useful security governance signals, but I did not find enough repository-level evidence to verify Article 14 operational readiness. The decisive gaps are manufacturer-awareness criteria, 24/7 escalation ownership, separate severe-incident and actively exploited vulnerability clocks, ENISA/CSIRT submission readiness, and proof that access-controlled evidence can be preserved without exposing restricted details.

**Action:** Repository security/operations owner SHOULD review the evidence gaps below and either link the access-controlled procedures and timestamp controls or confirm this repo relies on an external product-security process; accept when each `INCOMPLETE` / `NOT_ASSESSED` row has evidence or an explicit human decision.

`TARGET_REPO: github/gh-aw-firewall @ 42cf8f65ee3a3cc6387cd23c2ac20dcc84f458b0`

### Verified baseline
| Topic | Status | Evidence | Source |
|---|---|---|---|
| CRA baseline dates: entry into force 10 Dec 2024; CAB provisions 11 Jun 2026; Article 14 from 11 Sep 2026; full application 11 Dec 2027 | HUMAN_REVIEW_REQUIRED | Baseline checked against official Commission CRA page naming 27 July 2026 guidance and against the worker baseline contract; Eur-Lex text could not be retrieved in this sandbox, so final date confirmation still needs human review against the OJ text. Verified 2026-09-16. | source: { instrument: "Regulation (EU) 2024/2847", provision: "baseline applicability dates incl. Article 71 application schedule", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj ; Commission guidance page (non-binding): https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act |
| Commission CRA guidance dated 27 Jul 2026 is guidance, not binding law | EVIDENCE_SUFFICIENT | Commission CRA policy page includes the 27 July 2026 guidance reference. Verified 2026-09-16. | source: { instrument: "European Commission CRA guidance", provision: "guidance publication", authority: "non-binding" } — https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act |

### Responsibility and escalation map
| Requirement/topic | Status | Observed evidence | URL | Verification date |
|---|---|---|---|---|
| Public vulnerability intake path exists | EVIDENCE_SUFFICIENT | `docs/security.md` directs reporters to coordinated disclosure via `opensource-security[@]github.com` and says not to use public issues/PRs. | https://github.com/github/gh-aw-firewall/blob/42cf8f65ee3a3cc6387cd23c2ac20dcc84f458b0/docs/security.md | 2026-09-16 |
| Product-level owner, backup approver, and 24/7 escalation map for Article 14 events | INCOMPLETE | No repository evidence found for named owner, backup, after-hours path, or escalation roster. Public SECURITY contact alone is insufficient. | https://github.com/github/gh-aw-firewall/blob/42cf8f65ee3a3cc6387cd23c2ac20dcc84f458b0/docs/security.md | 2026-09-16 |
| Event-to-product mapping authority | NOT_ASSESSED | Repo describes AWF as a product/component, but no Article 14 mapping record was found linking incidents/vulns to reportable product scope. | https://github.com/github/gh-aw-firewall/blob/42cf8f65ee3a3cc6387cd23c2ac20dcc84f458b0/README.md | 2026-09-16 |

### Actively exploited vulnerability readiness
| Requirement/topic | Status | Observed evidence / gap | URL | Verification date |
|---|---|---|---|---|
| Awareness criteria distinct from detection time | INCOMPLETE | No procedure found defining when manufacturer awareness is established versus event occurrence/detection/reportability/submission. This is a critical clock-start gap for the 24h/72h/14d lifecycle. | not verified in repository checkout | 2026-09-16 |
| Early warning within 24h from established awareness | NOT_ASSESSED | No access-controlled runbook, decision record, or deadline monitor found. | not verified in repository checkout | 2026-09-16 |
| Vulnerability notification within 72h from established awareness | NOT_ASSESSED | No repository evidence of notification workflow, approval path, or submission proof controls. | not verified in repository checkout | 2026-09-16 |
| Final report within 14 days after corrective/mitigating measure available | NOT_ASSESSED | Repo has dependency-monitoring language about finding vulnerabilities within 24h, but not the Article 14 final-report trigger or corrective-measure tracking. | https://github.com/github/gh-aw-firewall/blob/42cf8f65ee3a3cc6387cd23c2ac20dcc84f458b0/.github/workflows/dependency-security-monitor.md | 2026-09-16 |
| Access-controlled evidence preservation for vuln description, severity/impact, malicious-actor info, corrective measure | INCOMPLETE | No evidence location or preservation procedure found; issue intentionally excludes restricted advisory/incident detail. | not verified in repository checkout | 2026-09-16 |
| User communication without undue delay after awareness | INCOMPLETE | Public disclosure intake exists, but no maintained process found for informing affected users independently of regulator notification completion. | https://github.com/github/gh-aw-firewall/blob/42cf8f65ee3a3cc6387cd23c2ac20dcc84f458b0/docs/security.md | 2026-09-16 |

### Severe incident readiness
| Requirement/topic | Status | Observed evidence / gap | URL | Verification date |
|---|---|---|---|---|
| Severe-incident threshold review record and human decision | HUMAN_REVIEW_REQUIRED | No repository evidence found; whether an event is a severe incident requires explicit human review. | not verified in repository checkout | 2026-09-16 |
| Early warning within 24h from established awareness | NOT_ASSESSED | No severe-incident runbook, clock monitor, or escalation evidence found. | not verified in repository checkout | 2026-09-16 |
| Incident notification within 72h from established awareness | NOT_ASSESSED | No repository evidence for notification submission readiness. | not verified in repository checkout | 2026-09-16 |
| Final report within one month after incident notification | NOT_ASSESSED | No procedure found for final-report tracking keyed to notification submission time. | not verified in repository checkout | 2026-09-16 |
| Intermediate status report on CSIRT coordinator request | NOT_ASSESSED | No request-handling or draft-maintenance path found. | not verified in repository checkout | 2026-09-16 |
| Mitigation and ongoing-measure evidence preservation | INCOMPLETE | No documented retention/preservation process specific to incident evidence was found in repo content reviewed. | not verified in repository checkout | 2026-09-16 |

### Timestamp provenance and clock-start controls
| Control | Status | Observed evidence | URL | Verification date |
|---|---|---|---|---|
| Distinct timestamps for occurred / detected / awareness established / reportability decision / submission | INCOMPLETE | Repository contains generic timestamp references in workflows/tests, but no controlled CRA-ready event chronology. | not verified in repository checkout | 2026-09-16 |
| Trusted timestamp source and audit trail | NOT_ASSESSED | No Article 14-specific timestamp provenance procedure found. | not verified in repository checkout | 2026-09-16 |
| Deadline monitoring and reminders | NOT_ASSESSED | No monitor for 24h, 72h, 14d, or 1 month Article 14 deadlines found. | not verified in repository checkout | 2026-09-16 |

### Critical gaps and recommendations
- **Critical gap:** No verifiable manufacturer-awareness rule or evidence source. Without that, SLA clocks MUST NOT be started from guessed timestamps.
source: { instrument: "Regulation (EU) 2024/2847", provision: "Article 14 reporting timelines as measured from manufacturer awareness", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj
- **Critical gap:** No repo-visible escalation/approval/backup path for Article 14 notifications or user communications.
- **Critical gap:** No separate documented readiness matrices for actively exploited vulnerabilities versus severe incidents.
- **Recommendation:** Link or reference access-controlled procedures covering awareness determination, regulatory decision records, ENISA single-reporting-platform readiness, national CSIRT coordination, proof of submission, evidence retention, and user communication.
- **Recommendation:** Label exercises clearly as tests and retain rehearsal records; none were verified here.

What's working: the repository does have a clear public vulnerability intake path and explicitly discourages public disclosure of security issues, which is a useful foundation for confidential triage.

Evidence reviewed

- `target/docs/security.md`
- `target/README.md`
- `target/.github/workflows/dependency-security-monitor.md`
- `target/.github/workflows/ci-doctor.md`
- `target/.github/workflows/file-permissions-checker.yml`
- bounded keyword inventory across the `target/` checkout for incident/security/reporting terms
- Commission CRA policy page: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act

Limitations:
- `gh issue list` and `gh search issues` were unavailable in this sandbox (`malformed version`), so duplicate-open-issue checking could not be completed through `gh`.
- Eur-Lex HTML retrieval returned no useful body in this sandbox, so the binding baseline dates remain flagged for human confirmation against the official OJ text.
- No access-controlled incident/advisory systems were available from this checkout, so missing evidence stays `INCOMPLETE` / `NOT_ASSESSED`.

### Human Acceptance
A non-bot reviewer SHOULD add a thumbs-up reaction only after reviewing the complete awareness criteria, escalation and backup paths, separate vulnerability and severe-incident timelines, timestamp controls, evidence preservation locations, critical gaps, and the required human reportability decisions.

### Control Plane
- Correlation ID: `35111435260-322`
- Central repository: `githubnext/gh-aw-cao`
- Control plane run URL: https://github.com/githubnext/gh-aw-cao/actions/runs/35111435260

> Generated by [:alarm_clock: EU CRA / Article 14](https://github.com/githubnext/gh-aw-cao/actions/runs/35112096881) · pi · gpt54 · 30 AIC · ⊞ 10.2K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Feu-cra-compliance-article-14-reporting-readiness%22&type=issues)
> - [x] expires on Oct 16, 2026, 3:03 PM UTC

Contributor guide

Open the contributing guide

Research direction

Start by reading docs/security.md, README.md, and .github/workflows/dependency-security-monitor.md, then review the listed gaps against any available access-controlled procedures. Done means every INCOMPLETE or NOT_ASSESSED row has linked evidence or an explicit human decision, including escalation ownership, separate timelines, timestamp controls, evidence retention, and user communication.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.