Observed arrival · 2026-08-31
Cidra ranks the software you actually run
Cidra accepts software inventories, resolves products to CPE or PURL identities, and ranks vulnerabilities using exploitation evidence rather than severity alone.
Field notes
Cidra takes an inventory rather than source code: rows from CSV, TSV, CycloneDX, or SPDX are resolved to CPE or PURL identities with an attached confidence value. Its workflow names six supported version schemes and applies VEX and vendor-backport information before prioritising findings with KEV, EPSS, exposure, and asset tier. The page says one resulting record can feed a ticket, evidence pack, and board summary without re-authoring.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue