Skip to content

[TASK] Add CRA conformity documents - #80

Merged
sbuerk merged 1 commit into
1from
task/cra-conformity-documents-1
Aug 27, 2026
Merged

[TASK] Add CRA conformity documents#80
sbuerk merged 1 commit into
1from
task/cra-conformity-documents-1

Conversation

@sbuerk

@sbuerk sbuerk commented Aug 27, 2026

Copy link
Copy Markdown
Member

Adds the CRA documents for this branch, taken verbatim from the
wv-people/cra repository (main, 18505c5), where they were reviewed and
approved. Nothing here is authored independently of that repository — it is the
single source of truth for these files.

What this branch gets

Package Version Highest TYPO3 End of support
web-vision/deepl-write 1.1.0 TYPO3 13 2027-12-31

Files added or updated at the repository root:

  • SECURITY.md — replaces the previous version. Supported Versions is now a
    table carrying an end-of-support date per major version, derived from the
    community-support end of the highest TYPO3 version that major supports.
  • EU-Declaration-of-Conformity.md and EU-Konformitaetserklaerung.md — the
    full EU declaration of conformity under Regulation (EU) 2024/2847, English
    and German, signed under VOLLMACHT-CISO-2026-01.
  • README.md — gains four sections at the end: Supported Versions, Security,
    Simplified EU Declaration of Conformity (Annex VI) and License. Existing
    content is untouched; a License section that already existed is kept as it is.

Why the Annex VI section in the README

CRA Annex VI requires the simplified declaration to state the exact internet
address of the full declaration. TER and Packagist build their product pages
from README.md, not from SECURITY.md, so the README is the only place that
reaches those distribution channels.

Scope rule

A major version is covered when the highest TYPO3 version it supports is still
in regular community support — TYPO3 13 until 2027-12-31, TYPO3 14 until
2029-06-30. TYPO3 12 went ELTS on 2026-04-30, so majors capped at 12 or below
are out of scope and get no declaration.


Scope: this is phase 1

The CRA repository's docs/TEMPLATE-README-EN.md defines the full set of
user-information sections required by Annex II of Regulation (EU) 2024/2847,
and explicitly says not to drop a section merely because it is short. This pull
request deliberately covers only the part that can be generated correctly and
identically for every extension:

Annex II Section Status
pt 2 Reporting a vulnerability in this PR
pt 6 EU Declaration of Conformity in this PR
pt 7 Security support & update policy in this PR
License in this PR
pt 1 Manufacturer (name, postal address, contact) open
pt 4 (2) Security environment & security properties open
pt 5 Known risks & foreseeable misuse open
pt 8.1 Installation & secure initial setup open
pt 8.2 Configuration changes & data security open
pt 8.3 Installing security updates open
pt 8.4 Uninstallation & data removal open
pt 8.5 Automatic security updates open
pt 8.6 Notes for integrators open
pt 9 Software Bill of Materials (SBOM) open

The open sections need per-product wording and are tracked in a separate issue
on this repository. Merging this PR does not make the product Annex II
complete — it establishes the reporting channel, the declaration link and the
supported-version statement, which are the parts with a hard external
dependency (the published declaration under /conformity/).

Adds the security policy and the EU declaration of conformity for
this release branch, taken verbatim from the wv-people/cra
repository (main, 18505c5), which is the single source of
truth for these documents.

SECURITY.md replaces the previous version: the supported versions
are a table now and carry an end of support date per major
version, derived from the community support end of the highest
TYPO3 version that major supports.

The README gains the simplified declaration under Annex VI with
the exact address of the full declaration, the supported version
table, the reporting channel and the license. TER and Packagist
build their product pages from the README rather than from
SECURITY.md, so that is the only place reaching those channels.
@sbuerk
sbuerk merged commit fa512e9 into 1 Aug 27, 2026
2 checks passed
@sbuerk
sbuerk deleted the task/cra-conformity-documents-1 branch August 27, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant