Observed arrival · 2026-09-16
CRA Watch turns vulnerability alerts into a compliance countdown
A dependency-monitoring tool that scans lockfiles or SBOMs against OSV.dev and the CISA Known Exploited Vulnerabilities catalog.
Field notes
The public scan accepts a lockfile or SBOM, checks up to 5,000 packages, and names OSV.dev and the CISA Known Exploited Vulnerabilities catalog as its sources. The page distinguishes installed or connected products from pure browser SaaS and lists plugins, SDKs, libraries, firmware, and mobile software among the cases it considers usually in scope. Its broader workflow is described as daily monitoring with alerts, draft ENISA reporting, reminders, and an audit trail.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue