Loading…
Tuesday October 6, 2026 10:30 - 10:50 CEST
On 8 Sept 2025, one phishing email hijacked a maintainer's npm account and pushed malicious versions of chalk, debug and 16 other packages totalling 2.6B weekly downloads. When such a package breaks something that hurts someone, who pays?
Two EU laws finalised in 2024 shape the answer, the Product Liability Directive and the Cyber Resilience Act, and their duties phase in across 2026 and 2027. So we go hands-on: we take this real compromise and walk it, step by step, down the liability chain. The maintainer, it turns out, is the one the law works hardest to shield as non-commercial open source sits largely outside both regimes. The bill lands downstream, on the commercial manufacturer who ships debug inside a product. Under the PLD, a missing security update can itself be a defect, under strict liability. The CRA adds a second layer since it lays a duty on to manage exactly this kind of vulnerability - detect it, report it, patch it - backed by fines, while the "open-source steward" carries a lighter, fine-free load.
Speakers
avatar for Annika Kristin Niemann

Annika Kristin Niemann

Lawyer, iRights.Law
Annika Niemann is a solicitor specialising in IT law, with a focus on open source compliance, supporting companies in the legally compliant use of open source software across the supply chain. She advises on CRA and product liability questions, including how the EU's Cyber Resilience... Read More →
Tuesday October 6, 2026 10:30 - 10:50 CEST
South Hall 3B-3C

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link