KEV detection
Cross-checks every SBOM component against CISA’s Known Exploited Vulnerabilities catalog — the 1% that hackers are using right now.
OSP.0.1.0 · PurpleLotus
The CLI that builds an SBOM, cross-checks every component against CISA KEV, and tells you which dependencies are actively exploited in the wild — not merely have a CVE.
v2026.09.30 · 1,730 in catalog · 2026-09-30
CVE-2026-76504 Cisco Catalyst SD-WAN Manager · CVE-2026-86950 Apple Multiple Products · CVE-2026-88772 Citrix NetScaler · CVE-2026-88771 Citrix NetScaler · CVE-2026-67279 MikroTik RouterOS · CVE-2026-65660 Microsoft SharePoint · CVE-2026-87902 WordPress Core · CVE-2026-5430 WSO2 Multiple Products · CVE-2026-76504 Cisco Catalyst SD-WAN Manager · CVE-2026-86950 Apple Multiple Products · CVE-2026-88772 Citrix NetScaler · CVE-2026-88771 Citrix NetScaler · CVE-2026-67279 MikroTik RouterOS · CVE-2026-65660 Microsoft SharePoint · CVE-2026-87902 WordPress Core · CVE-2026-5430 WSO2 Multiple Products
1,730
known exploited in the wild
Added (7d)
9
Due (14d)
2
Ransomware
361
polling CISA…
We asked a narrower question
Most vulnerability tooling stops at “this package has a CVE.” That produces a lot of tickets and very little prioritization: a scanner that flags every CVE in your dependency tree, regardless of whether it is actually being exploited, trains teams to ignore the output.
Osprey narrows the question to the one that actually matters for triage — is this specific component, at this specific version, known to be exploited right now?
a new signal
CISA’s KEV catalog tracks vulnerabilities known to have been exploited in the wild. Osprey correlates that with the dependencies found in a project.
version-aware
OSV decides whether your installed version is affected, not_affected, or unknown. Unknown is never treated as affected.
more like triage
Confidence tiers, remediation paths, SARIF, and --fail-on-high. Software can branch on the result instead of drowning in a CVE dump.
Triage, not theater
Based on a typical npm lockfile run against CISA KEV — not a count of every CVE in NVD.
Osprey
2
known-exploited, version-affected packages
Audit completed in 1.42s · exit 1 with --fail-on-high
Typical CVE scanner
1,847
CVEs flagged, regardless of exploitation
Hours of triage · most tickets never move
Built for the gate
Cross-checks every SBOM component against CISA’s Known Exploited Vulnerabilities catalog — the 1% that hackers are using right now.
high is a PURL-backed exact match. low is a name/vendor coincidence. Never panic over a string collision.
OSV decides whether your installed version is actually affected — not whether the package ever had a CVE.
Point cra at owner/repo. No clone. Private repos take a GitHub token.
Ed25519 signatures in a DSSE envelope, with tamper detection, so the inventory is verifiable.
JSON results, GitHub Actions job summaries, inline annotations, SARIF, and --fail-on-high for the gate.
Interactive · cra 0.1.0
Same commands as the real binary. Audit the demo app, a clean tree, or facebook/react. Flags: --verbose, --summary, --fail-on-high. This is a faithful in-browser tty of Purplelotusec/Osprey.
Enter · ↑ history · Tab complete · Ctrl+C
osprey 0.1.0 — cra demo tty
Type a command or click a preset. Try `cra --help`.
How it works
cra --path /path/to/your/project cra --url owner/repo cra --path . --fail-on-high --output results.json
Software / Repository
Dependencies
SBOM
Vulnerability analysis
CISA KEV match
Security signal
Investigate & respond
| versionStatus | Meaning |
|---|---|
| affected | OSV evidence covers the installed version |
| not_affected | Available evidence excludes the installed version |
| unknown | Evidence couldn't be established — never treated as affected |
We give a FAQ
Osprey is an open-source CLI for software supply chain visibility. cra is the command. It builds a Software Bill of Materials from your project, cross-checks every component against the CISA KEV catalog, and tells you which dependencies are actively exploited in the wild — not merely “have a CVE.”
Osprey notes
Sep 19, 2026 · Launch
Security visibility for the software supply chain. Why KEV, how version status works, and what Osprey will not claim about the EU CRA.
README · 0.1.0
cra, cra-sbom, cra-kev, cra-report. Confidence tiers, structured JSON, and the things we are honest about not supporting yet.
Get started
git clone https://github.com/Purplelotusec/Osprey cd Osprey npm install npm link cra --path .