Features for CRA Compliance
Build-time SBOMs, vulnerability tracking and the evidence your Cyber Resilience Act process needs
SBOM Generation
CRACI records the SBOM during the build. A package-aware proxy observes what each job actually fetches, including packages restored from CI caches, and every SBOM carries a completeness state. Export it in CycloneDX or SPDX, with transitive dependencies and declared licenses, and know exactly what is in the software you ship.
Learn more โVulnerability Tracking
CRACI keeps re-evaluating monitored SBOMs as new vulnerabilities are published and aggregates findings across builds and repositories. Security teams triage what it finds and send it to the teams that own the fix, with VEX support. The SBOMs you collect from your own vendors are monitored alongside your builds.
Learn more โCompliance Reports
Export the evidence your CRA process needs: build-time SBOMs, vulnerability records and signed provenance that links each artifact to the build that produced it. Reports export as PDF, HTML, CSV, Excel and JSON for your technical documentation. CRACI automates a significant part of the supply chain visibility and evidence your CRA process needs.
Learn more โCI/CD Integration
CRACI replaces the runner, not GitHub Actions. Change runs-on to craci and your runs still appear in GitHub. Every job records what it fetched and runs under an egress policy that is validated before the job starts and fails closed. GitHub Actions is supported today; other CI systems are on the roadmap.
Learn more โ