CRAIR CRA Readiness Snapshot

contentful/rich-text · package.json · 20 Jul 2026, 11:40 UTC
11 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
30
dependencies in scope
2
known vulnerabilities
0
actively exploited (CISA KEV)
1.4%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.

⚠ No lockfile — SBOM is not reproducible

This scan is based on a manifest (package.json), not a lockfile. 8 of 30 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.

All findings (2)

PackageVersionAdvisorySeverityEPSSFixed inSummary
rollup dev ^4.18.0 CVE-2026-27606 HIGH 1.4% 2.80.0 Rollup 4 has Arbitrary File Write via Path Traversal
rollup dev ^4.18.0 CVE-2024-47068 HIGH 0.7% 3.29.5 DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS

SBOM summary

30 direct dependencies scanned (22 pinned to exact versions) from package.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us