Know when the clock may have started.
Scan a public GitHub repository for known vulnerabilities and CISA Known Exploited Vulnerabilities, then preserve a timestamped review trail for EU Cyber Resilience Act readiness.
This prototype reads public dependency manifests only. It does not certify CRA compliance and does not submit anything to ENISA.
0
Dependencies parsed
0
Known vulnerabilities
0
CISA KEV matches
0
Manifests found
Signals
Evidence first
Keep the source, CVE, dependency version and detection timestamp together instead of relying on memory.
Known exploitation
Cross-check OSV vulnerability results against the public CISA KEV catalogue.
Human decision
The product surfaces signals. A person decides applicability, exploitability and whether reporting is legally required.