embtrace-check
Free CRA Readiness Check collector — one command in your project folder, and within 24 hours you receive a report showing where your product stands with the EU Cyber Resilience Act: traffic-light readiness status, your full component inventory, and known vulnerabilities with severity.
This collector is open source for one reason: so you can verify exactly what leaves your machine.
What it transmits — and what it never does
Transmitted (JSON, ~a few kB):
- names, versions and package ecosystems of your dependencies (from lockfiles and build files: Conan, vcpkg, CMake, Cargo, npm/yarn/pnpm, Python, Go, Maven/Gradle, Meson, and more),
- the project folder name (hash it with
--anonymize), - scan statistics (number of build files, tool version).
Never transmitted: source code, file paths, file contents, configuration, credentials. See for yourself before sending anything:
embtrace-check . --dry-run # prints the exact payload, uploads nothing
Usage
- Get your free one-time code at https://embtrace.dev/check (the report goes to the e-mail address you register there).
- Run the collector in your project folder:
pipx install embtrace-check # or: pip install embtrace-check,
# or download the standalone binary
embtrace-check . --code CHK-XXXX-YYYY
- Your report arrives within 24 hours. The code is valid for one check.
More options: embtrace-check --help — including --output payload.json
for air-gapped environments (send the file by mail) and --with-tools to
additionally use native package-manager CLIs for higher-fidelity results.
Exit codes
| Code | Meaning |
|---|---|
| 0 | success |
| 1 | error (network, invalid code, …) |
| 2 | no components found — declare dependencies manually in embtrace-deps.yaml |
Privacy
Data is processed exclusively on Innomatica's own servers in Germany and is never shared or sold. Full notes: https://embtrace.dev/check-privacy.
About
embtrace-check is the free entry point to
embtrace — the CRA/NIS2 compliance toolchain for
embedded software teams by Innomatica GmbH.
The server side (enrichment, vulnerability monitoring, reports) is a
commercial product; this repository contains the complete client.
Maintained by Innomatica; the roadmap follows the product. Issues and PRs are welcome — please report security topics per SECURITY.md.
License
MIT © 2026 Innomatica GmbH
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file embtrace_check-0.2.0.tar.gz.
File metadata
- Download URL: embtrace_check-0.2.0.tar.gz
- Upload date:
- Size: 52.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
23331d66c573ce8cdab928b8e39d62ddefbdc9804515a1e5659bfd3f8740fa89
|
|
| MD5 |
0cc21343f6c619c8b07dcbb0b13c314e
|
|
| BLAKE2b-256 |
965815ed123c6cc8879fed0c2c67b386ea051d63c922b6de190d08b066ed6931
|
Provenance
The following attestation bundles were made for embtrace_check-0.2.0.tar.gz:
Publisher:
publish.yml on Innomatica-GmbH/embtrace-check
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
embtrace_check-0.2.0.tar.gz -
Subject digest:
23331d66c573ce8cdab928b8e39d62ddefbdc9804515a1e5659bfd3f8740fa89 - Sigstore transparency entry: 2582878658
- Sigstore integration time:
-
Permalink:
Innomatica-GmbH/embtrace-check@2be625da3649337cfc568b835fcd8fbbdbd6b8e3 -
Branch / Tag:
refs/tags/v0.2.0 - Owner: https://github.com/Innomatica-GmbH
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@2be625da3649337cfc568b835fcd8fbbdbd6b8e3 -
Trigger Event:
push
-
Statement type:
File details
Details for the file embtrace_check-0.2.0-py3-none-any.whl.
File metadata
- Download URL: embtrace_check-0.2.0-py3-none-any.whl
- Upload date:
- Size: 64.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
bfae2e323053208b187e775cc7d13e3f17c5c804a9e6ab32fe2a0399c5c2b8da
|
|
| MD5 |
80ded657ad9172fd2fb242c52414ec2d
|
|
| BLAKE2b-256 |
d97d973efe1c2c61866c18d0317e2daf70fd61398f2fd41656cc2a3af74336b7
|
Provenance
The following attestation bundles were made for embtrace_check-0.2.0-py3-none-any.whl:
Publisher:
publish.yml on Innomatica-GmbH/embtrace-check
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
embtrace_check-0.2.0-py3-none-any.whl -
Subject digest:
bfae2e323053208b187e775cc7d13e3f17c5c804a9e6ab32fe2a0399c5c2b8da - Sigstore transparency entry: 2582878661
- Sigstore integration time:
-
Permalink:
Innomatica-GmbH/embtrace-check@2be625da3649337cfc568b835fcd8fbbdbd6b8e3 -
Branch / Tag:
refs/tags/v0.2.0 - Owner: https://github.com/Innomatica-GmbH
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@2be625da3649337cfc568b835fcd8fbbdbd6b8e3 -
Trigger Event:
push
-
Statement type: