Free public scan
Get a CRA Readiness Snapshot before it becomes a surprise.
Point Threadcairn at one public GitHub repository. Get the bounded dependency inventory, vulnerability coverage, and potential CRA-relevant signals that deserve a human review.
01 / bounded
Read only what matters.
The first pass reads public repository metadata, bounded tree entries, and supported dependency manifests from the default branch.
02 / normalized
Useful, not overclaimed.
Exact package versions become a normalized in-memory component inventory. Raw scan inputs and results are not persisted; only anonymous aggregate funnel events are.
03 / honest
Coverage stays visible.
Rate limits, truncation, and unavailable vulnerability lookups remain visible instead of becoming false confidence or a legal conclusion.