EU Cyber Resilience Act
Fendora Security Directory
Open security reference for packages, CVEs, and licenses, updated daily. CRA implications where our editorial team has reviewed them.
Packages
CVE counts and license data for widely-used open-source packages.
CVEs
Vulnerabilities with Article 14 and CRA obligations.
Licenses
SPDX licenses and manufacturer stewardship risks.
Ecosystems
npm, PyPI, Maven, and Cargo CRA readiness scores.
Check your repo with Fendora
Scan your SBOM for CRA-relevant vulnerabilities and license risks.
Get started