I've updated my blog post on the worries about open source and the EU Cyber Resilience Act to reflect that the agreed upon #CRA text appears to be a lot better for open source and free software. But we still await the final details, when I get those I'll do another writeup.
https://berthub.eu/articles/posts/eu-cra-best-open-source-security/