Dmytro Galko · open-source tools

cra-report

EU Cyber Resilience Act Article 14 reporting tool

Since 11 September 2026 a manufacturer placing a product with digital elements on the EU market has 24 hours to notify ENISA of an actively exploited vulnerability in it. Finding vulnerabilities is not the hard part - any scanner hands you a hundred. cra-report says which of them starts the statutory clock, and drafts the Article 14 notification for the ones that do.

What it does

How it is proved

On a dependency tree containing log4j-core 2.14.1 it reports 2 findings with a deadline out of 19 advisories, both flagged as used in ransomware campaigns. On lodash 4.17.15 it reports 0 out of 6 - equally worth being able to say.

TypeScript28 testsno runtime dependenciesno API key

People find this looking for

CRA Article 14 reporting tool, actively exploited vulnerability 24 hours, ENISA notification, SBOM KEV cross-reference.

If that is your week and you would rather someone else did it, write to hello@dkautomation.dev or open an issue.