Sep23
- Speaker
CRACI x Startup-säätiö x Kyberala x Illusian x Avance: Panel discussion
· Helsinki, Finland
Software supply chains are the #1 attack surface. CRACI helps companies ship secure releases with automated SBOMs, vulnerability tracking, and audit-ready evidence right from your CI/CD.
Backed by
CRACI organizes supply chain security around four connected workspaces — from your first build to your next audit.
Builds
Security
Inventory
Compliance
Featured
Whether you're shipping a single microservice or managing hundreds of repositories, CRACI brings supply chain security to every build.
Generate a provably complete Software Bill of Materials directly from CRACI's build runner. CycloneDX and SPDX formats supported.
Continuous vulnerability management with real-time monitoring across all your dependencies.
Generate CRA-ready SBOM reports and vulnerability disclosures for ENISA with one click.
Runs as your GitHub Actions runner, with your runs still in GitHub. Other CI systems are on the roadmap.
Assign vulnerabilities, track remediation progress, and coordinate disclosures.
Research
We rebuild the full CVE record from the CVE Program's official
cvelistV5 repository every day and publish what
it shows. In 2026 the rate is still climbing.
CVEs published per day
One every 6 minutes in 2026
High or Critical per day
Up from 54 per day in 2025
Records analysed since 2020
Rebuilt daily from the CVE Program's cvelistV5