What we watch
CRA Desk matches your SBOM against vulnerability advisories for the package ecosystems below. Anything outside them is not matched and the panel counts it as a gap rather than reporting it as clean.
Package ecosystems
| Ecosystem | purl type | Example |
|---|---|---|
| npm | npm | pkg:npm/lodash@4.17.21 |
| PyPI | pypi | pkg:pypi/django@5.0.1 |
| Maven | maven | pkg:maven/org.slf4j/slf4j-api@2.0.9 |
| Go | golang | pkg:golang/github.com/gin-gonic/gin@v1.9.1 |
| crates.io | cargo | pkg:cargo/serde@1.0.195 |
| NuGet | nuget | pkg:nuget/Newtonsoft.Json@13.0.3 |
| RubyGems | gem | pkg:gem/rails@7.1.2 |
| Packagist | composer | pkg:composer/symfony/console@7.0.1 |
| Hex | hex | pkg:hex/phoenix@1.7.10 |
| Alpine | apk | - |
List verified against OSV on 2026-09-21. OSV schema, defined ecosystems
Not watched
- System packages from Debian, Ubuntu and other distributions. Alpine is watched, but only for the releases CRA Desk has data for - a release past its end of life, or edge, is flagged Needs review rather than matched.
- Container images built on anything but Alpine. An SBOM of an image is mostly system packages, so a Debian- or Ubuntu-based image reports mostly gaps.
- Components with no purl - first-party code, vendored sources, binaries. Without a package identity there is nothing to match against.
- Components with a purl but no version. These are flagged for review rather than resolved, because a range cannot be evaluated against an unknown version.
- Product versions you have decommissioned. That is your decision, made per version in the panel: from then on the version gets no new matches or alerts, and uploads under its label are refused. The panel marks it as not watched, so its silence is not read as "no vulnerabilities".
Why a match can say “Needs review”
A match is watched, found and shown - but the version comparison could not be completed. We report that rather than resolving it, because turning “we could not tell” into “not affected” is the one direction that hides exposure. It happens in five ways:
- The SBOM lists the component without a version, so there is nothing to compare against the advisory's affected range.
- The component's version could not be read as a semantic version, so it could not be placed inside or outside the advisory's affected range.
- The advisory's affected range names a boundary version we could not read, so we could not tell which side of it the component falls on.
- The advisory states its affected versions in the ecosystem's own version scheme, and either this version or the range uses a qualifier (rc, milestone, -jre and the like) that we do not order - so the component's version was never placed inside or outside it.
- The advisory names the package without naming any affected versions, so there is no range to compare the component against.
- The component names a distribution release we have no data for, so it could not be checked against the advisory.
- The component's version does not match its distribution's version format, so it could not be compared to the advisory's affected range.
In all five cases the match stays open and counted until a person decides. The first of them is the same gap the “Watched, no version” count above reports.
Sources and what each one does
- OSV - the matcher
- Advisories are fetched into our own corpus and evaluated against your component versions here, so your dependency inventory is never sent to a third party.
- CISA KEV - exploited-flag source
- Raises the priority of an existing match and can start the Article 14 clock; never produces a match on its own.
- EU KEV (via EUVD) - second source
- ENISA's EU KEV dump. Like CISA KEV, never produces a match on its own - only raises priority and can start the Article 14 clock.
- NVD - the CVSS score
- Queried by CVE after a match exists, only to attach a severity score. It is never used to find a match: CPE matching cannot be explained component by component and an unexplainable hit is worse than none.
Listing is evidence of exploitation (Article 3(42)), not the definition of "actively exploited" - and not being listed is not evidence that it isn't.
These counts describe reach, not detection. A component being watched means we can match an advisory against it - not that an advisory exists, or that every advisory is complete.