Repository check for the Cyber Resilience Act
Paste a public GitHub repository. We read what GitHub shows publicly and tell you what is in place and what is missing: a security policy with a contact, an exportable SBOM, releases and activity. Nothing to prepare, and the check runs in your browser.
Known vulnerabilities
Pressing the button sends the package URLs (names and versions) from GitHub's dependency export to the public OSV database at api.osv.dev, and nothing else.
The check reads public GitHub data through GitHub's API from your browser; GitHub allows 60 unauthenticated requests an hour per address and one check uses about six. These are signals from public data, not a compliance assessment: a missing signal can mean the project keeps it elsewhere.
Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.