Dmytro Galko · open-source tools
EU Cyber Resilience Act Article 14 reporting tool
Since 11 September 2026 a manufacturer placing a product with digital elements on the EU market has 24 hours to notify ENISA of an actively exploited vulnerability in it. Finding vulnerabilities is not the hard part - any scanner hands you a hundred. cra-report says which of them starts the statutory clock, and drafts the Article 14 notification for the ones that do.
On a dependency tree containing log4j-core 2.14.1 it reports 2 findings with a deadline out of 19 advisories, both flagged as used in ransomware campaigns. On lodash 4.17.15 it reports 0 out of 6 - equally worth being able to say.
CRA Article 14 reporting tool, actively exploited vulnerability 24 hours, ENISA notification, SBOM KEV cross-reference.
If that is your week and you would rather someone else did it, write to hello@dkautomation.dev or open an issue.