CISA KEV × your lockfiles

Did today's KEV hit your lockfiles?

Get a Slack message when a new CISA KEV entry matches a package in your committed lockfiles or SBOMs. Quiet otherwise.

Start prepaid pilot · $99/mo

Package-match alerts · no auto-PRs

Illustrative Slack notification

DepKEVTo your channel

KEV match

A new KEV entry matches a package in your lockfile.

Repo
[Repository]
Package
[Package@version]
CVE
[CVE ID]
Sources
CISA KEV · OSV

Placeholder fields. Source links appear with an actual match.

The check behind the message.

  1. Read the committed inventory.

    Use your lockfiles or SBOMs as the package inventory for the pilot.

  2. Match new KEV entries.

    Map CVE identifiers through OSV/GHSA to the packages and versions in that inventory.

  3. Send the match to Slack.

    The notification identifies the repository, package and CVE, with source links for your review.

Keep Dependabot or Snyk in your workflow. DepKEV adds a KEV-specific check against what you pin. Your team reviews the match and handles the patch.

Prepaid pilot

Check it against your lockfiles.

Agree the inventory and Slack destination for the pilot.

$99 / month

Start prepaid pilot

About the signal

When does DepKEV send a Slack message?

When a new CISA KEV entry matches a package in your committed lockfiles or SBOMs. The message includes the repository, package, CVE and source links. No match means no notification.

Does DepKEV replace Dependabot or Snyk?

No. DepKEV checks new KEV entries against your package inventory. It does not provide a full SCA workflow or open patch pull requests.

Do you stop breaches?

No. DepKEV reports package matches so your team can investigate. It does not verify exploitability, prevent exploitation or replace your patch process.

Who is the pilot for?

AppSec and platform engineers who maintain committed lockfiles or SBOMs and want KEV-specific package alerts in Slack.