Skip to the card

Card 196 of 9852026-09-16 issue

Observed arrival · 2026-09-16

CRA Watch turns vulnerability alerts into a compliance countdown

crawatch.dev Observed source
Editorial interest 79/100 Selection signal · not a rating of the site

A dependency-monitoring tool that scans lockfiles or SBOMs against OSV.dev and the CISA Known Exploited Vulnerabilities catalog.

Landing page captured for the 2026-09-16 issue.

Field notes

The public scan accepts a lockfile or SBOM, checks up to 5,000 packages, and names OSV.dev and the CISA Known Exploited Vulnerabilities catalog as its sources. The page distinguishes installed or connected products from pure browser SaaS and lists plugins, SDKs, libraries, firmware, and mobile software among the cases it considers usually in scope. Its broader workflow is described as daily monitoring with alerts, draft ENISA reporting, reminders, and an audit trail.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
$PaidCommerce or pricing visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use

One card from the complete issue

Wiring Is Not Learning

428,563 arrived 1,000 judged 985 catalogued Enter the complete issue
crawatch.dev

Landing page observed 2026-09-16. The live site may have changed.