# FOSS component register (A1.2)

A simple register of the open source components integrated into your product. It supports traceability, due diligence, and lifecycle monitoring, and can be maintained in a spreadsheet, SharePoint, Git, or any internal tool.

| Component name | Version | Used in | Criticality | Exposure | License | Maintainer activity | Last vulnerability review | Update owner | Notes |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| ExampleAuthLib | 2.4.1 | Authentication module | High | Public | MIT | Active (monthly releases) | 12 Feb 2026 | CTO | Security-sensitive. CVE-2025-XXXX patched in v2.4.1. Continuous monitoring enabled. |
|   |   |   |   |   |   |   |   |   |   |
|   |   |   |   |   |   |   |   |   |   |
|   |   |   |   |   |   |   |   |   |   |

- **Criticality:** Low / Medium / High
- **Exposure:** Internal / Limited / Public

---

_Based on OCCTET deliverable D2.3 – CRA Adoption Best Practice Document (v1.0, March 2026), licensed under CC BY 4.0._

<https://occtet.eu/best-practices/checklists-and-templates/>
