<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability Management on OpenChain KWG</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/vulnerability-management/</link><description>Recent content in Vulnerability Management on OpenChain KWG</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 10 Aug 2026 11:20:08 +0900</lastBuildDate><atom:link href="https://OpenChain-Project.github.io/OpenChain-KWG/en/tags/vulnerability-management/index.xml" rel="self" type="application/rss+xml"/><item><title>What the US AI Executive Order (2026-06-02) Means for Enterprise Open Source Managers</title><link>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><guid>https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/</guid><description>&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The executive order &amp;ldquo;Promoting Advanced Artificial Intelligence Innovation and Security,&amp;rdquo; signed on June 2, 2026, imposes no obligations on enterprises. Its substance is the Treasury Department-led AI Cybersecurity Clearinghouse (a relay body that pools, verifies, and distributes vulnerability information, to be established within 30 days) and a voluntary pre-disclosure framework for frontier models (to be designed within 60 days); mandatory licensing and pre-approval are explicitly excluded &lt;a id="a1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#a1"&gt;A1&lt;/a&gt;. No provision applies directly to enterprise open source managers either. Still, there is a reason to read this order: the context behind it. AI finding open source vulnerabilities faster than humans do has already become reality. Ahead of the executive order, an unreleased Anthropic model found 6,202 high- or critical-severity vulnerabilities in open source projects over two months, and patching has not kept pace &lt;a id="a6-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#a6"&gt;A6&lt;/a&gt;·&lt;a id="c1-ref-1"&gt;&lt;/a&gt;&lt;a href="https://OpenChain-Project.github.io/OpenChain-KWG/en/blog/2026/06/10/us-ai-eo-ospo/#c1"&gt;C1&lt;/a&gt;. What open source managers need to prepare is not compliance with the executive order, but a response system that can handle a check of patch-processing capacity, cleanup of end-of-life (EOL) components, and the EU Cyber Resilience Act reporting obligation taking effect September 11, 2026, all at once.&lt;/p&gt;</description></item></channel></rss>