Free browser tool checks EU CRA Article 14 compliance via dependency lockfiles
A developer has released a free, browser-based tool at cra.toledotechnologies.com/check that lets users check software dependencies for EU Cyber Resilience Act Article 14 obligations by pasting common lockfiles or SBOMs. Under Article 14, enforceable from 11 September 2026, companies must notify their national CSIRT and ENISA within 24 hours if a vulnerability in their EU-market product is being actively exploited. The tool cross-references declared dependencies against the OSV.dev advisory database and CISA's Known Exploited Vulnerabilities catalogue, with all processing done locally in the browser and no file contents sent to the developer's servers. A companion GitHub Action, cra-watch, is also available for automated CI pipeline checks across twelve lockfile formats. The developer cautions that a KEV match does not automatically trigger a reporting obligation, and that reachability of the vulnerable code path remains a key factor under the European Commission's July 2026 guidance.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in