DepKEV · AppSec Slack bot
Did today’s CISA KEV hit your lockfiles?
We watch the KEV catalog and ping Slack only when a new exploited CVE matches packages in your committed lockfiles or SBOMs. Not another SCA firehose.
$99/mo prepaid pilot
- KEV feed → OSV/GHSA → your lockfiles
- Slack on hit (repo, package, CVE, link)
- No auto-PRs. Signal only.
Or email claudio.moletta@silentgrid.com
FAQ
How do you validate? One evening: current KEV × three lockfiles → hit table. Then five prepaid asks.
Who is this for? AppSec/platform with npm, pip, or Go lockfiles who care about KEV day, not every CVE.