Selling an iOS or Mac app in the EU? Since 11 Sep, the Cyber Resilience Act requires reporting actively exploited vulnerabilities within 72h.
cra-scan (free, open source) builds your SBOM from Package.resolved and flags exactly those.
github.com/stavrop/cra-scan
#iOSDev #Swift #CRA
github.com
GitHub - stavrop/cra-scan: SBOM + exploited-vulnerability check for Swift / Apple-platform projects (EU Cyber Resilience Act)
SBOM + exploited-vulnerability check for Swift / Apple-platform projects (EU Cyber Resilience Act) - stavrop/cra-scan