Know when the clock may have started.

Scan a public GitHub repository for known vulnerabilities and CISA Known Exploited Vulnerabilities, then preserve a timestamped review trail for EU Cyber Resilience Act readiness.

This prototype reads public dependency manifests only. It does not certify CRA compliance and does not submit anything to ENISA.
Evidence first

Keep the source, CVE, dependency version and detection timestamp together instead of relying on memory.

Known exploitation

Cross-check OSV vulnerability results against the public CISA KEV catalogue.

Human decision

The product surfaces signals. A person decides applicability, exploitability and whether reporting is legally required.

Prototype limits. v0.3 supports public repositories and selected root manifests/SBOMs: package-lock.json, pinned requirements.txt, pyproject.toml, go.mod, Cargo.lock, composer.lock, Gemfile.lock and sbom.json (CycloneDX/SPDX). A vulnerability or KEV match is a technical signal, not proof that a specific product is exploitable or reportable under the CRA. CRA applicability depends on the product, market role, scope and facts of the event.