opencra is an Apache-2.0 Python package for assessing Cyber Resilience Act Article 14 reporting readiness from software bills of materials. It uses vulnerability and security data to help DevSecOps teams identify issues that may start a 24-hour reporting clock.
In the Application security & vulnerability scanning space, opencra takes a focused approach. It focuses on determining which SBOM vulnerabilities trigger the Cyber Resilience Act's 24-hour reporting requirement. It is built as an open-source project for devSecOps and software security teams. The project is open source (Apache-2.0). It runs on the command line, and it can be self-hosted.
opencra first shipped in 2026. Among its 7 catalogued features are SBOM analysis, CRA assessment, and vulnerability matching.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match