SBOMs that follow releases
Generate and maintain software bills of materials from connected GitHub repositories, with a release-by-release history you can actually explain.
Threadcairn turns dependency and vulnerability signals into a reviewable CRA trail for small teams, without pretending a snapshot is a legal conclusion.
Start with a public, read-only scan or follow the onboarding handoff for your own public or private repositories.
Why Threadcairn
The CRA asks for a living view of your product. Threadcairn keeps the technical facts close to the people who ship, so review starts with context instead of a spreadsheet hunt.
Generate and maintain software bills of materials from connected GitHub repositories, with a release-by-release history you can actually explain.
Monitor dependencies for known and actively exploited vulnerabilities, then turn a noisy alert into a focused CRA review when the context calls for it.
Capture discovery time, affected products and versions, CVE details, evidence, mitigations, and reporting deadlines in one guided workflow.
The working loop
A calm, repeatable path for teams that need evidence without hiring a compliance department.
Point Threadcairn at a GitHub repository and get a baseline SBOM for each release.
Track dependencies, CVEs, and active exploitation signals before they disappear into a backlog.
Open a guided review with discovery time, affected versions, mitigations, and deadline context.
Keep the facts connected from first signal to resolved release. Threadcairn prepares the information for customer review; your team makes the decision.
Start with one repository
Get a free repository scan, then choose the level of ongoing coverage that fits your products and your team.
Threadcairn prepares reporting information for customer review. It does not provide legal advice or decide whether an incident is legally reportable.