Evidence, not promises
Under the EU Cyber Resilience Act, the question is rarely whether you care about security. It is whether you can show the trail: releases, vulnerability handling, decisions, timelines.
The minimum useful pack
- Versioned release ledger.
- Vulnerability intake → fix → release linkage.
- SBOM references per release.
- Decision log for exceptions and risk acceptances.
Where GitHub fits
Engineering already records most of this in repos, releases and advisories. The gap is assembly: scattered signals, assembled under pressure. GitHub-native evidence tooling closes that gap without asking teams to live in a second system.
Related: ForgeVault CRA
Operational background, not legal advice. Confirm CRA obligations with counsel.