KEV match
Placeholder fields. Source links appear with an actual match.
CISA KEV × your lockfiles
Get a Slack message when a new CISA KEV entry matches a package in your committed lockfiles or SBOMs. Quiet otherwise.
Start prepaid pilot · $99/moPackage-match alerts · no auto-PRs
Illustrative Slack notification
Use your lockfiles or SBOMs as the package inventory for the pilot.
Map CVE identifiers through OSV/GHSA to the packages and versions in that inventory.
The notification identifies the repository, package and CVE, with source links for your review.
Keep Dependabot or Snyk in your workflow. DepKEV adds a KEV-specific check against what you pin. Your team reviews the match and handles the patch.
Prepaid pilot
Agree the inventory and Slack destination for the pilot.
When a new CISA KEV entry matches a package in your committed lockfiles or SBOMs. The message includes the repository, package, CVE and source links. No match means no notification.
No. DepKEV checks new KEV entries against your package inventory. It does not provide a full SCA workflow or open patch pull requests.
No. DepKEV reports package matches so your team can investigate. It does not verify exploitability, prevent exploitation or replace your patch process.
AppSec and platform engineers who maintain committed lockfiles or SBOMs and want KEV-specific package alerts in Slack.