SBOM
Knows what you ship
Reads 12 lockfile formats across npm, PyPI, Maven (Gradle), Go, Cargo, RubyGems and Packagist, and writes a CycloneDX 1.6 SBOM, a machine-readable SBOM format the CRA accepts.
EU Cyber Resilience Act . Article 14 . Applies from 11 September 2026
If you make software or a connected product sold in the EU and one of its components is being actively exploited, you have 24 hours to send an early warning, 72 hours to notify, and 14 days after a fix is available to file the final report. CRA Clock watches every dependency so you find out first.
Free and open source, Apache-2.0. A GitHub Action that runs in your own CI.
Departures
Article 14 also covers severe incidents; CRA Clock handles actively exploited vulnerabilities in your dependencies.
Live board
The newest entries in CISA's Known Exploited Vulnerabilities catalog, read live through this site and cached for up to six hours. If one of these is in something you ship to the EU, your clock may already be running.
Source: CISA KEV catalog. CRA Clock does not add, rank or interpret these entries.
Runs in your browser
Drop any of the 12 lockfile formats CRA Clock reads: package-lock.json, npm-shrinkwrap.json, yarn.lock, pnpm-lock.yaml, requirements.txt, poetry.lock, Pipfile.lock, go.mod, Cargo.lock, Gemfile.lock, composer.lock or gradle.lockfile. Renamed files are recognised by their content.
Your lockfile never leaves your browser. Only package names and versions are sent to OSV.dev, and only CVE ids to FIRST. Privacy
How it works
SBOM
Reads 12 lockfile formats across npm, PyPI, Maven (Gradle), Go, Cargo, RubyGems and Packagist, and writes a CycloneDX 1.6 SBOM, a machine-readable SBOM format the CRA accepts.
Exploited, not just vulnerable
Every component is checked against OSV, then CISA's KEV catalog and FIRST's EPSS. Only evidence of exploitation starts the clock; high EPSS gets a warning. A failed lookup is flagged for manual review, never quietly passed.
Article 14
One issue per actively exploited vulnerability with the 24h and 72h deadlines, the fix version, and pre-filled early warning and notification drafts. The clock never resets on re-runs.
VEX
A CycloneDX VEX file marks each vulnerability in triage, with KEV and EPSS evidence attached, ready to share with customers and authorities.
What lands in your repo
CRA Art. 14: actively exploited CVE-2021-44228 in org.apache.logging.log4j:log4j-core 2.14.1
| Component | log4j-core 2.14.1 |
|---|---|
| Evidence | CISA KEV, added 2021-12-10, known ransomware use |
| EPSS | 94.4% (percentile 100) |
| Fixed in | 2.15.0, 2.12.2, 2.3.1 |
CRA Article 14 clock
Draft: 24 hour early warning
Draft: 72 hour notification
{ "bomFormat": "CycloneDX", "specVersion": "1.6", "metadata": { "component": { "name": "Acme Router", "version": "v4.2.0" } }, "components": [ { "type": "library", "name": "org.apache.logging.log4j:log4j-core", "version": "2.14.1", "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1", "properties": [{ "name": "cra-clock:files", "value": "gradle.lockfile" }] } ] }
vex.cdx.json and report.md, the job summary.Install
Add this workflow. It runs on every push to main and every six hours, because the KEV catalog changes daily.
name: cra-clock on: push: { branches: [main] } schedule: [{ cron: '17 */6 * * *' }] permissions: { contents: read, issues: write } jobs: clock: runs-on: ubuntu-latest steps: - uses: actions/checkout@v5 with: { persist-credentials: false } - uses: GautamTalksDev/cra-clock@v1 with: { product-name: Acme Router }
For the strongest supply chain guarantee, pin the full commit SHA of a release instead of the tag, and let Dependabot bump it:
- uses: GautamTalksDev/cra-clock@<full-40-character-commit-sha> # v1.0.0
Fork pull requests get a read-only token, so issues cannot be opened. CRA Clock then falls back to the job summary with a note. To keep runs clean, set open-issues: false on pull_request events.
- uses: GautamTalksDev/cra-clock@v1 with: open-issues: ${{ github.event_name != 'pull_request' }}
Fare
FreeFree and open source (Apache-2.0). A hosted dashboard may come later.
CRA Clock prepares drafts and evidence. It is not legal advice and does not submit anything for you. Article 14 applies to manufacturers of products with digital elements made available on the EU market, and covers both actively exploited vulnerabilities and severe incidents; CRA Clock handles actively exploited vulnerabilities in your dependencies. Check whether your product is in scope. Exploitation evidence comes from the CISA KEV catalog, which is one reliable source among several; if you learn of exploitation another way, your clock started then.