ambolt

Check your GitHub repository for Cyber Resilience Act readiness in ten seconds

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) makes manufacturers of software and connected products responsible for how they handle vulnerabilities. Reporting of actively exploited vulnerabilities is already mandatory since 11 September 2026; the rest applies from 11 December 2027. Before you read the Regulation, it is useful to know what your repository already shows, because several expectations map to things a repository can have or lack.

What a repository can show

The repository check reads public GitHub data and reports these signals:

It does not decide whether you are compliant. A missing signal can mean you keep the thing elsewhere, and a present signal says nothing about quality. Think of it as a starting list.

Three ways to run it

In the browser, with nothing uploaded: paste owner/name at ambolt.dev/cra/repo-check. It calls GitHub's public API from your browser, so the 60-requests-an-hour limit is yours, not shared.

From the command line, with no dependencies:

npx @ambolt/cra repo owner/name
npx @ambolt/cra sbom bom.json --osv --min 7
npx @ambolt/cra licences bom.json --project proprietary --out THIRD-PARTY-NOTICES.md

In CI, as a pull-request check:

- uses: ambolt-dev/cra-check@v1
  with:
    sbom: bom.json
    min-checks: 7
    project-licence: proprietary
    repo-check: true

What to fix first

If the check reports a missing policy, generate a security.txt and a disclosure policy and commit the policy as SECURITY.md. If the SBOM has no suppliers or relationships, your build tool can usually produce a richer one than GitHub's export: CycloneDX tools exist for npm, Python, Go, Rust and Java, and the SBOM checker shows what each file lacks.

Information only, not legal advice; check the Regulation for your product. The classifier tells you which category your product probably falls in.

Try it free: npm package vulnerability checker runs the same call in your browser (one free check per tool and IP address per day). API reference

More from the blog

Data and prices change; every API response states its source and date. Informational only, not financial, legal or tax advice.