Skip to main content

OpenCRA

CRA Article 14 reporting starts 11 September 2026. Know if you have a CISA KEV hit in one command.

OpenCRA is the open-source CLI and GitHub Action for Software Bills of Materials and actively-exploited vulnerability candidates. CRA-Shield is the optional hosted control plane for team workspaces, the 24-hour awareness clock, and SRP-ready evidence packs.

A scanner hit is a candidate, never legal awareness. Article 14 clocks start only after a human assessment. OpenCRA does not file with ENISA, does not claim CE marking, and is not a notified body.

uvx opencra scan .

Why not just Syft or Grype?

Tool What it does
Syft Generates an SBOM
Grype / osv-scanner Finds known CVEs
OpenCRA Tells you which findings are CISA KEV hits — the ones that may start a 24-hour CRA clock after you become aware

Install

# Requires Anchore Syft on PATH
brew install syft          # macOS
# Linux: https://github.com/anchore/syft#installation

pipx install opencra
# or run without installing:
uvx opencra doctor
uvx opencra scan .

Quickstart

opencra doctor
opencra kev refresh
opencra scan . --fail-on kev
opencra scan . --format cyclonedx --output sbom.cdx.json
opencra scan . --export-pdf cra-report.pdf
opencra report --last
# Demo a KEV candidate (exit 1). Not legal awareness; do not auto-file.
opencra scan examples/sample-kev.cdx.json --fail-on kev

GitHub Action

- uses: crwncode/opencra@v1
  with:
    fail-on: kev

Legal disclaimer

OpenCRA prepares evidence and highlights Known Exploited Vulnerabilities. It does not:

  • start the Article 14 legal clock automatically
  • file notifications on the ENISA Single Reporting Platform
  • certify CRA compliance or CE marking

The 24-hour early warning and 72-hour notification run from awareness. The 14-day final report for actively exploited vulnerabilities runs from when a corrective measure is available, not from detection. Severe incidents have a one-month final report after the 72-hour notification.

CRA-Shield (optional hosted control plane)

uv sync --all-packages --group dev
uv run uvicorn opencra_api.main:app --app-dir apps/api --reload
cd apps/web && npm install && npm run dev

See docs/saas.md. --sync-cloud on the CLI posts scans to /v1/ingest.

Open core

The CLI, Action, Syft wrapper, OSV + KEV matching, and local reports are Apache 2.0. CRA-Shield (hosted clocks, audit trail, SRP packs, SSO) is commercial. See docs/cli.md.

License

Apache License 2.0. Copyright 2026 CodeLancaster.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

opencra-0.1.4.tar.gz (8.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

opencra-0.1.4-py3-none-any.whl (6.7 kB view details)

Uploaded Python 3

File details

Details for the file opencra-0.1.4.tar.gz.

File metadata

  • Download URL: opencra-0.1.4.tar.gz
  • Upload date:
  • Size: 8.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for opencra-0.1.4.tar.gz
Algorithm Hash digest
SHA256 263585c3aa48e5b28a3f220c1a16f319bf1bf8e5f242b291cb5362116c01246f
MD5 a701c20db6e61b1ab58e22a045e98246
BLAKE2b-256 45548dea4a2e4ba5b816ac160fc098090aa2a890357a8f0402f4eafdc0d0fd42

See more details on using hashes here.

Provenance

The following attestation bundles were made for opencra-0.1.4.tar.gz:

Publisher: publish.yml on crwncode/opencra

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opencra-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: opencra-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 6.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for opencra-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 7ae7e8984936598bc727d356a02a87189261a7ff41ef0919e9ec827283dabc3f
MD5 8d171761336d0edcb5c47ca9269dc955
BLAKE2b-256 1cfbac7bdc6e46f8c6d84f8aeae0337a3f9c1932e52953784d9c642ffa0b4396

See more details on using hashes here.

Provenance

The following attestation bundles were made for opencra-0.1.4-py3-none-any.whl:

Publisher: publish.yml on crwncode/opencra

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.1.6

2 files

0.1.5

2 files

This release

0.1.4 This release

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page