ambolt

CRA Index

The Cyber Resilience Act makes manufacturers responsible for the open-source components they ship. This index shows, for 300 popular packages, which public security signals are in place: security policy, maintenance, known advisories, provenance and more. One page per package, refreshed weekly, with a badge you can put in your README.

300

packages indexed from npm and PyPI

66 %

have a security policy that the Scorecard can find

39 %

publish signed releases or build provenance

Browse

How to read a page

Each page lists nine signals, each tied to what the Act asks of a manufacturer. A pass means the signal is present in public data today. Missing means it is not, which can also mean the project keeps it elsewhere. Unknown means the data is not published. The signals are a starting point for your own due diligence, not a verdict on a project or its maintainers.

Data

deps.dev (generated data, CC BY 4.0), OSV advisories through deps.dev and the OpenSSF Scorecard. Each page shows the date the data was read. Machine-readable results per package are published as JSON under /cra/index/data/.

Want the same check for your own repository? Run the repository check.

Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.