Skip to main content

OpenCRA

CRA Article 14 reporting starts 11 September 2026. Know if you have a CISA KEV hit in one command.

OpenCRA is the open-source CLI and GitHub Action for Software Bills of Materials and actively-exploited vulnerability candidates. CRA-Shield is the optional hosted control plane for team workspaces, the 24-hour awareness clock, and SRP-ready evidence packs.

A scanner hit is a candidate, never legal awareness. Article 14 clocks start only after a human assessment. OpenCRA does not file with ENISA, does not claim CE marking, and is not a notified body.

uvx opencra scan .

Why not just Syft or Grype?

Tool What it does
Syft Generates an SBOM
Grype / osv-scanner Finds known CVEs
OpenCRA Tells you which findings are CISA KEV hits — the ones that may start a 24-hour CRA clock after you become aware

Install

# Requires Anchore Syft on PATH
brew install syft          # macOS
# Linux: https://github.com/anchore/syft#installation

pipx install opencra
# or
uvx opencra doctor

Quickstart

opencra doctor
opencra kev refresh
opencra scan . --fail-on kev
opencra scan . --format cyclonedx --output sbom.cdx.json
opencra scan . --export-pdf cra-report.pdf
opencra report --last

GitHub Action

- uses: CodeLancasterX/opencra@v1
  with:
    fail-on: kev

Legal disclaimer

OpenCRA prepares evidence and highlights Known Exploited Vulnerabilities. It does not:

  • start the Article 14 legal clock automatically
  • file notifications on the ENISA Single Reporting Platform
  • certify CRA compliance or CE marking

The 24-hour early warning and 72-hour notification run from awareness. The 14-day final report for actively exploited vulnerabilities runs from when a corrective measure is available, not from detection. Severe incidents have a one-month final report after the 72-hour notification.

CRA-Shield (optional hosted control plane)

uv sync --all-packages --group dev
uv run uvicorn opencra_api.main:app --app-dir apps/api --reload
cd apps/web && npm install && npm run dev

See docs/saas.md. --sync-cloud on the CLI posts scans to /v1/ingest.

Open core

The CLI, Action, Syft wrapper, OSV + KEV matching, and local reports are Apache 2.0. CRA-Shield (hosted clocks, audit trail, SRP packs, SSO) is commercial. See docs/cli.md.

License

Apache License 2.0. Copyright 2026 CodeLancaster.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

opencra-0.1.0.tar.gz (8.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

opencra-0.1.0-py3-none-any.whl (6.7 kB view details)

Uploaded Python 3

File details

Details for the file opencra-0.1.0.tar.gz.

File metadata

  • Download URL: opencra-0.1.0.tar.gz
  • Upload date:
  • Size: 8.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for opencra-0.1.0.tar.gz
Algorithm Hash digest
SHA256 339e11d91a4ff5358b7f5670079112b7f39465a50cb7539095b5cda3fefc7eaa
MD5 12682171eee9b43faa8c597adb91af7c
BLAKE2b-256 676c66c6b97047fe1f28075d97933885d806d8578ab904052b61e5ba4225929e

See more details on using hashes here.

Provenance

The following attestation bundles were made for opencra-0.1.0.tar.gz:

Publisher: publish.yml on crwncode/opencra

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opencra-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: opencra-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 6.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for opencra-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 e55c7dcb1514ec5162bf53c8792a9c02e6f7cb5b36b7f43a87605aaa6d183fa5
MD5 45cd13bc89529a5a01d3b86ef4279271
BLAKE2b-256 c768278288282cb087e11bdddbcafca966b6d7c63ae1296bfd6574e5d993d19e

See more details on using hashes here.

Provenance

The following attestation bundles were made for opencra-0.1.0-py3-none-any.whl:

Publisher: publish.yml on crwncode/opencra

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page