Skip to main content

embtrace-check

Free CRA Readiness Check collector — one command in your project folder, and within 24 hours you receive a report showing where your product stands with the EU Cyber Resilience Act: traffic-light readiness status, your full component inventory, and known vulnerabilities with severity.

This collector is open source for one reason: so you can verify exactly what leaves your machine.

What it transmits — and what it never does

Transmitted (JSON, ~a few kB):

  • names, versions and package ecosystems of your dependencies (from lockfiles and build files: Conan, vcpkg, CMake, Cargo, npm/yarn/pnpm, Python incl. uv, Go, Maven/Gradle, Meson, and more),
  • names and versions of FPGA IP cores (AMD/Xilinx Vivado .hwh/.xci, Microchip Libero Tcl/.cxf, Intel/Altera Quartus *_hw.tcl),
  • the project folder name (hash it with --anonymize),
  • scan statistics (number of build files, tool version),
  • only if you wrote them yourself in embtrace-deps.yaml: the supplier, license, purl and CPE entries of your declaration — a declaration is written for SBOM purposes, so it travels by default and makes your report complete (58 instead of 17 attributed licenses on a typical Zephyr project). Withhold it with --no-declared-metadata. Discovered components never carry these fields.

Never transmitted: source code, file paths, file contents, configuration, credentials. The supplier of a detected FPGA IP core is known locally but deliberately not transmitted — a supplier you declare yourself in embtrace-deps.yaml is your statement and does travel. See for yourself before sending anything:

embtrace-check . --dry-run     # prints the exact payload, uploads nothing

Build outputs (dist/, build/, node_modules/, …) and hidden directories are never scanned. Project-specific excludes go into a committed .embtraceignore at the project root — one glob pattern per line, # comments.

Usage

  1. Get your free one-time code at https://embtrace.dev/check (the report goes to the e-mail address you register there).
  2. Run the collector in your project folder:
pipx install embtrace-check         # or: pip install embtrace-check,
                                    #     or download the standalone binary
embtrace-check . --code CHK-XXXX-YYYY
  1. Your report arrives within 24 hours. The code is valid for one check.

More options: embtrace-check --help — including --output payload.json for air-gapped environments (send the file by mail) and --with-tools to additionally use native package-manager CLIs for higher-fidelity results.

Exit codes

Code Meaning
0 success
1 error (network, invalid code, …)
2 no components found — declare dependencies manually in embtrace-deps.yaml

Privacy

Data is processed exclusively on Innomatica's own servers in Germany and is never shared or sold. Full notes: https://embtrace.dev/check-privacy.

About

embtrace-check is the free entry point to embtrace — the CRA/NIS2 compliance toolchain for embedded software teams by Innomatica GmbH. The server side (enrichment, vulnerability monitoring, reports) is a commercial product; this repository contains the complete client.

Maintained by Innomatica; the roadmap follows the product. Issues and PRs are welcome — please report security topics per SECURITY.md.

License

MIT © 2026 Innomatica GmbH

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

embtrace_check-0.5.0.tar.gz (64.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

embtrace_check-0.5.0-py3-none-any.whl (70.5 kB view details)

Uploaded Python 3

File details

Details for the file embtrace_check-0.5.0.tar.gz.

File metadata

  • Download URL: embtrace_check-0.5.0.tar.gz
  • Upload date:
  • Size: 64.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for embtrace_check-0.5.0.tar.gz
Algorithm Hash digest
SHA256 9a213be29bfbae838ff012bbf048f5ec822bec671c715ddc9a9babc10a79131a
MD5 cc883094b6e4800ef62539116a4e8c45
BLAKE2b-256 6649f806afd9c748e1cdf46da2e68385d9041f69ac83ac640671a7652f51a1dc

See more details on using hashes here.

Provenance

The following attestation bundles were made for embtrace_check-0.5.0.tar.gz:

Publisher: publish.yml on Innomatica-GmbH/embtrace-check

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file embtrace_check-0.5.0-py3-none-any.whl.

File metadata

  • Download URL: embtrace_check-0.5.0-py3-none-any.whl
  • Upload date:
  • Size: 70.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for embtrace_check-0.5.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9f888b3362659d4dcf7345182b4fe5e03fed0ae0015ba353d4c6000971467725
MD5 5fd7de6f664828b14bb45057ea4836de
BLAKE2b-256 c1e072c311502a8f700745eb0ebb653754afaf9bd7d80b967841a5155e1fedfb

See more details on using hashes here.

Provenance

The following attestation bundles were made for embtrace_check-0.5.0-py3-none-any.whl:

Publisher: publish.yml on Innomatica-GmbH/embtrace-check

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.5.0 This release

2 files

0.4.0

2 files

0.3.1

2 files

0.3.0

2 files

0.2.0

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page