<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Abin</title>
    <description>The latest articles on DEV Community by Abin (@abin_johnson).</description>
    <link>https://dev.to/abin_johnson</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4129040%2F00d2ce5b-cbf6-45ec-afd1-c1d7273d64ea.png</url>
      <title>DEV Community: Abin</title>
      <link>https://dev.to/abin_johnson</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/abin_johnson"/>
    <language>en</language>
    <item>
      <title>The EU Cyber Resilience Act's 24-hour clock started on 11 September: who it covers, and a free way to check your dependencies</title>
      <dc:creator>Abin</dc:creator>
      <pubDate>Thu, 17 Sep 2026 10:41:01 +0000</pubDate>
      <link>https://dev.to/abin_johnson/the-eu-cyber-resilience-acts-24-hour-clock-started-on-11-september-who-it-covers-and-a-free-way-g2a</link>
      <guid>https://dev.to/abin_johnson/the-eu-cyber-resilience-acts-24-hour-clock-started-on-11-september-who-it-covers-and-a-free-way-g2a</guid>
      <description>&lt;p&gt;&lt;em&gt;Developer, not a lawyer. Every claim below has an article number so you can check it against the text of Regulation (EU) 2024/2847 on EUR-Lex. Not legal advice.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The short version
&lt;/h2&gt;

&lt;p&gt;On 11 September 2026 the reporting obligations of the EU Cyber Resilience Act (CRA) started to apply. If you supply software commercially into the EU, and you become aware that a vulnerability in it is being actively exploited, you now owe ENISA an early warning within 24 hours, a notification within 72 hours, and a final report 14 days after a fix is available. That applies to a solo developer selling a game on Steam or an app on the App Store exactly as it applies to a large vendor, and it applies regardless of where you live.&lt;/p&gt;

&lt;p&gt;The rest of the regulation (SBOM, CE marking, a security support period of at least five years, the conformity paperwork) applies from 11 December 2027. This article is about the part that is live now.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the CRA is, in two paragraphs
&lt;/h2&gt;

&lt;p&gt;Regulation (EU) 2024/2847 was published in November 2024 and entered into force on 10 December 2024. It sets cybersecurity requirements for "products with digital elements": software and hardware, and their remote data processing, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network (Article 2(1), Article 3(1)). It is a product regulation in the CE-marking family, like the toy safety or radio equipment directives, and it is enforced by national market-surveillance authorities.&lt;/p&gt;

&lt;p&gt;Article 71 staggers application. Most obligations: 11 December 2027. Chapter IV on notified bodies: 11 June 2026. Article 14, the manufacturer's reporting obligations: &lt;strong&gt;11 September 2026&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Article 14: the three clocks
&lt;/h2&gt;

&lt;p&gt;Article 14(1) says a manufacturer shall notify any actively exploited vulnerability contained in the product that it becomes aware of. The notification goes simultaneously to the CSIRT designated as coordinator in the relevant member state and to ENISA, through the single reporting platform ENISA operates under Article 16. Article 14(2) sets the timing:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;(a) an early warning within 24 hours&lt;/strong&gt; of becoming aware, indicating at least the member states in which the product is available;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;(b) a vulnerability notification within 72 hours&lt;/strong&gt;, with general information about the product, the nature of the exploit and the vulnerability, and the corrective or mitigating measures taken and that users can take;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;(c) a final report no later than 14 days after a corrective or mitigating measure is available&lt;/strong&gt;, with a description of the vulnerability, its severity and impact, information about the actor if available, and details of the security update.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Article 14(3) to (5) apply the same 24-hour and 72-hour steps to "severe incidents having an impact on the security of the product", with a final report within one month. Article 14(8) adds that the manufacturer must inform impacted users without undue delay, and where appropriate all users, about the vulnerability and the measures they can take.&lt;/p&gt;

&lt;p&gt;Nothing here requires you to have fixed anything within 24 hours. It requires you to have &lt;em&gt;said something&lt;/em&gt; within 24 hours.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is a manufacturer
&lt;/h2&gt;

&lt;p&gt;Article 3(13): the natural or legal person who develops or manufactures a product with digital elements, or has it developed or manufactured, and markets it under their name or trademark, whether for payment, monetisation or free of charge. The trigger is supply in the course of a commercial activity (Recital 15 and 18), which includes charging for the product, charging for support beyond cost recovery, or monetising through advertising or data collection.&lt;/p&gt;

&lt;p&gt;So, in scope:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A paid game on Steam, itch or a console store, from a studio of any size, in any country.&lt;/li&gt;
&lt;li&gt;A paid or ad/IAP-funded app on the App Store or Google Play.&lt;/li&gt;
&lt;li&gt;Desktop software you sell or license, including an Electron or Tauri client for a web service.&lt;/li&gt;
&lt;li&gt;Browser extensions, plugins, themes and SDKs supplied commercially.&lt;/li&gt;
&lt;li&gt;Self-hosted software your customers install.&lt;/li&gt;
&lt;li&gt;Firmware in any device you sell.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Location does not matter. The test is that the product is made available on the EU market. If a customer in Germany can buy it, it is.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is mostly not
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Software as a service.&lt;/strong&gt; Recital 12 states that the regulation is not meant to apply to SaaS. The exception is "remote data processing" (Article 3(2)): processing at a distance, designed and developed by the manufacturer, without which the product could not perform one of its functions. In practice: a web app used in a browser is out; a mobile app plus the backend it cannot work without is in, backend included; a desktop client for your SaaS is in.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Free and open-source software&lt;/strong&gt; supplied outside a commercial activity (Recital 18 and 19). Publishing a library on GitHub under MIT does not make you a manufacturer. Selling a commercial licence or paid support for it does. Integrating it into your commercial product makes &lt;em&gt;you&lt;/em&gt; responsible for it as a component (Article 13(5)).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Products already covered by sector rules&lt;/strong&gt;: medical devices, motor vehicles, civil aviation, marine equipment (Article 2(2) to (4)), and products developed exclusively for national security or defence.&lt;/p&gt;

&lt;h2&gt;
  
  
  The definitional hinge: "actively exploited"
&lt;/h2&gt;

&lt;p&gt;This is where most of the anxiety in developer forums is misplaced. The CRA does not ask you to report every CVE in your dependency tree. Article 3(42) defines an actively exploited vulnerability as one "for which there is reliable evidence that execution of malicious code was performed by an actor on a system without permission of the system owner".&lt;/p&gt;

&lt;p&gt;That is materially narrower than "vulnerable" and has nothing to do with CVSS. A 9.8 with no observed exploitation does not start a clock. A 6.5 that is being used in the wild does, once you become aware.&lt;/p&gt;

&lt;p&gt;For a dependency you ship, the earliest public evidence of exploitation is usually one of two things: the CVE being added to CISA's Known Exploited Vulnerabilities (KEV) catalog, or a vendor or CSIRT advisory that explicitly says "exploited in the wild". KEV's inclusion criteria (an assigned CVE, reliable evidence of active exploitation, and a clear remediation action) are close to the CRA's definition, which makes it the right feed to watch. It is not the only evidence, and a KEV listing for a library is not proof that your product is exploitable. It is the point at which a reasonable person starts finding out, fast.&lt;/p&gt;

&lt;h2&gt;
  
  
  What "becoming aware" means for a small team
&lt;/h2&gt;

&lt;p&gt;The regulation does not define awareness. The sensible reading, and the one I would want to defend to an authority, is: when someone in your company knows, or when public information you could reasonably be expected to monitor says so about a component you ship. That second half is the practical problem. A three-person studio is not reading the KEV feed every morning, so the first they hear of an exploited vulnerability in their networking library is a customer, a journalist, or the authority.&lt;/p&gt;

&lt;p&gt;The fix is not a document. It is a daily job.&lt;/p&gt;

&lt;h2&gt;
  
  
  Penalties, honestly
&lt;/h2&gt;

&lt;p&gt;Article 64(1): non-compliance with the essential requirements in Annex I or the obligations in Articles 13 and 14 carries administrative fines of up to €15,000,000 or 2.5% of worldwide annual turnover, whichever is higher. Article 64(2): other obligations, up to €10,000,000 or 2%.&lt;/p&gt;

&lt;p&gt;Article 64(10) carves out two things. Open-source software stewards are not fined. And microenterprises and small enterprises (under 10 staff and €2M turnover, or under 50 staff and €10M, per Recommendation 2003/361/EC) are not subject to fines for failing to meet the &lt;strong&gt;24-hour deadline for the early warning&lt;/strong&gt; specifically. The 72-hour notification and the 14-day final report still carry the full fines. Enforcement is by national authorities, and for a non-EU micro studio the realistic first consequence is a takedown request to the store or an information request, not a fine in the post. Neither is pleasant at hour 23.&lt;/p&gt;

&lt;h2&gt;
  
  
  A minimal, defensible process
&lt;/h2&gt;

&lt;p&gt;Six things, all of which fit on one page:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Know what you ship.&lt;/strong&gt; A lockfile or a CycloneDX SBOM per product, per release, stored with the release. &lt;code&gt;package-lock.json&lt;/code&gt;, &lt;code&gt;Cargo.lock&lt;/code&gt;, &lt;code&gt;go.sum&lt;/code&gt;, &lt;code&gt;Package.resolved&lt;/code&gt;, &lt;code&gt;gradle.lockfile&lt;/code&gt;, &lt;code&gt;packages.lock.json&lt;/code&gt;, &lt;code&gt;Podfile.lock&lt;/code&gt;, or &lt;code&gt;syft&lt;/code&gt;/&lt;code&gt;cyclonedx-*&lt;/code&gt; output. An SBOM becomes an explicit requirement in December 2027 anyway (Annex I Part II).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Check it against OSV.dev.&lt;/strong&gt; OSV indexes npm, PyPI, crates.io, Go, Maven, NuGet, Packagist, RubyGems, Pub, Hex and Swift packages by repository URL. One &lt;code&gt;querybatch&lt;/code&gt; call per thousand packages.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Intersect with KEV.&lt;/strong&gt; Take every finding's ID and aliases and match them against the &lt;code&gt;cveID&lt;/code&gt; field of the KEV JSON. Those matches, and only those, are candidate "aware" events.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Re-run daily.&lt;/strong&gt; The clock runs on vulnerabilities that became exploited while you shipped nothing. On-push scanning does not catch that; a scheduled job does.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timestamp what you knew.&lt;/strong&gt; Append-only: a commit, an object with a retention lock, an email to yourself. This is the evidence of when the 24 hours began.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pre-draft the early warning.&lt;/strong&gt; Product name, version, the member states where it is sold, the vulnerability ID, a one-line description, contact details. Put the ENISA platform URL next to it. Calendar the 72-hour and 14-day follow-ups the moment you file.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The 40-line check
&lt;/h2&gt;

&lt;p&gt;Here is the core of steps 2 and 3 in Node, for an npm lockfile. Adapt the parser for your ecosystem; the OSV and KEV parts are the same everywhere.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="nx"&gt;fs&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;node:fs&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;lock&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;parse&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;fs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;readFileSync&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;package-lock.json&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;utf8&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;queries&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Object&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;entries&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;lock&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;packages&lt;/span&gt; &lt;span class="o"&gt;??&lt;/span&gt; &lt;span class="p"&gt;{})&lt;/span&gt;
  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;filter&lt;/span&gt;&lt;span class="p"&gt;(([&lt;/span&gt;&lt;span class="nx"&gt;p&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;p&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;version&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;map&lt;/span&gt;&lt;span class="p"&gt;(([&lt;/span&gt;&lt;span class="nx"&gt;p&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;package&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;p&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;node_modules/&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;pop&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="na"&gt;ecosystem&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;npm&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="na"&gt;version&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;version&lt;/span&gt; &lt;span class="p"&gt;}));&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;kev&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nf"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;r&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;exploited&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;Set&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;kev&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;vulnerabilities&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;map&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;v&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;cveID&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;hits&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[];&lt;/span&gt;
&lt;span class="k"&gt;for &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;let&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="nx"&gt;queries&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;+=&lt;/span&gt; &lt;span class="mi"&gt;1000&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;chunk&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;queries&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;slice&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;i&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;i&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="mi"&gt;1000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nf"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;https://api.osv.dev/v1/querybatch&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;method&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;POST&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;body&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;stringify&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;queries&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;chunk&lt;/span&gt; &lt;span class="p"&gt;})&lt;/span&gt; &lt;span class="p"&gt;}).&lt;/span&gt;&lt;span class="nf"&gt;then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;r&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
  &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;results&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;forEach&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="nx"&gt;r&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;j&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;r&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;vulns&lt;/span&gt; &lt;span class="o"&gt;??&lt;/span&gt; &lt;span class="p"&gt;[]).&lt;/span&gt;&lt;span class="nf"&gt;forEach&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;v&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;hits&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;push&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;pkg&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;chunk&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;j&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="na"&gt;id&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt; &lt;span class="p"&gt;})));&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;for &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;h&lt;/span&gt; &lt;span class="k"&gt;of&lt;/span&gt; &lt;span class="nx"&gt;hits&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;vuln&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nf"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`https://api.osv.dev/v1/vulns/&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;h&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;`&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;r&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;ids&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;vuln&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;...(&lt;/span&gt;&lt;span class="nx"&gt;vuln&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;aliases&lt;/span&gt; &lt;span class="o"&gt;??&lt;/span&gt; &lt;span class="p"&gt;[])];&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;onKev&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;ids&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;filter&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;exploited&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;has&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;id&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
  &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;onKev&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;length&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;EXPLOITED&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;h&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;pkg&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="kr"&gt;package&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;h&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;pkg&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;version&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;onKev&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;,&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;Date&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;toISOString&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Run it from cron every morning and pipe the output somewhere you cannot edit quietly. That is most of the control. If you would rather not run it yourself, I built a free web version: paste any lockfile at &lt;a href="https://crawatch.dev/?ref=devto" rel="noopener noreferrer"&gt;crawatch.dev&lt;/a&gt;, no signup, and it does the OSV and KEV steps and gives you a shareable result page. There is a paid daily-watch version with the countdown and the early-warning draft; the free scan is the part most people need today.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to do this week if you are in scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Produce the dependency list for each product you sell in the EU.&lt;/li&gt;
&lt;li&gt;Run the check once. If nothing is on KEV, write that down with the date; that is also evidence.&lt;/li&gt;
&lt;li&gt;Write the one-page incident procedure: who owns the 24 hours, where the ENISA platform is, the three deadlines, the draft.&lt;/li&gt;
&lt;li&gt;Put a security contact on your website and store page. A coordinated vulnerability disclosure policy and a contact address become explicit requirements in December 2027 (Annex I Part II), and you want the address to exist before someone needs it.&lt;/li&gt;
&lt;li&gt;If you are a pure SaaS, read Recital 12, exhale, and check whether you ship a client.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Open questions I would like answers to
&lt;/h2&gt;

&lt;p&gt;How coordinating CSIRTs will treat a KEV hit in a transitive dependency your product never calls. Whether Apple, Google and Valve will be treated as distributors under Article 20, with their own duties to act on non-conforming products. And whether anyone has yet filed through the single reporting platform and can say what the form actually asks for. If you know, the comments are open, or &lt;a href="mailto:hello@crawatch.dev"&gt;hello@crawatch.dev&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;CRA Watch is run by one developer who read the regulation. Not legal advice.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>eu</category>
      <category>gamedev</category>
      <category>webdev</category>
    </item>
  </channel>
</rss>
