Preparing another presentation on the EU Cyber Resilience Act, and this part remains WILD. If you embed an open source component in your product, and you find a vulnerability in there you SHALL report it to the open source upstream. And if you have a fix, you should send that too: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CONSIL:ST_17000_2023_INIT