EU Cyber Resilience Act: checking Swift package dependencies for actively exploited vulnerabilities

Since 11 September 2026, the EU Cyber Resilience Act requires anyone selling software in the EU - including paid iOS and Mac apps - to report actively exploited vulnerabilities in their products: an early warning within 24 hours, a notification within 72 hours, through ENISA's reporting platform. It also covers app versions already on sale.

The practical first question for most of us is "does anything I ship depend on a package with a known exploited vulnerability?" I couldn't find a tool that treats Swift Package Manager as a first-class ecosystem, so I wrote a small open-source one:

  • reads Package.resolved (v1-v3) and Podfile.lock
  • writes a CycloneDX 1.6 SBOM (useful later for the CRA technical documentation)
  • checks each pinned package against OSV, and marks findings as exploited if CISA's KEV list or ENISA's EUVD lists them
  • runs locally, in Xcode Cloud or as a GitHub Action, and only fails the build on exploited issues by default
pipx install cra-scan

GitHub repo (Apache-2.0, no dependencies)

Two things worth knowing: micro and small companies can't be fined for missing the 24-hour early warning (Art. 64), but the 72-hour notification still applies. The rest of the CRA (technical file, support period, CE marking) applies from 11 December 2027, and for most apps it's self-assessment.

How are others approaching this?

Feedback on missed matches is very welcome, especially for CocoaPods, which the tool can't match yet.

EU Cyber Resilience Act: checking Swift package dependencies for actively exploited vulnerabilities
 
 
Q