Observed arrival · 2026-09-07
Threadcairn, a CRA Evidence Trail for Small Teams
A repository-connected tool that turns dependency and vulnerability signals into a reviewable CRA readiness record.
Field notes
The workflow begins with a GitHub repository and builds a baseline SBOM for each release, then links dependency signals to a guided review record. The sample readiness board shows 142 tracked dependencies, three queued events, and a CVE-2025-4428 recommendation against the example project northstar-api. The page says records can include discovery time, affected versions, evidence, mitigations, owners, status, and deadlines, while leaving the legal decision to the customer.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue