Drupal is a registered trademark of Dries Buytaert
Release: Paragraphs 8.x-1.23 Minor update available for module paragraphs (8.x-1.23). Release: AI (Artificial Intelligence) 1.4.6 Minor update available for module ai (1.4.6). Release: AI (Artificial Intelligence) 1.3.11 Minor update available for module ai (1.3.11). Release: Search and Replace Scanner 2.0.0 Major update available for module scanner (2.0.0). Release: Chosen 5.0.7 Minor update available for module chosen (5.0.7). Release: Instagram Feed Block 1.0.2 Minor update available for module instagram_feed_block (1.0.2). Release: Mercury Editor Page Templates 1.0.10 Minor update available for module mercury_editor_page_templates (1.0.10). Release: Content Packages 1.1.0 Minor update available for module content_packages (1.1.0). Module Revived: Entity Browser 8.x-2.16 Module entity_browser updated after 11 months of inactivity (8.x-2.16). Usage Milestone: Media entity Twitter Module media_entity_twitter crossed 10,000 active installs.

Proofwright CRA Evidence sends this site's software inventory — Drupal core plus every installed module and theme — to your Proofwright console as a CycloneDX SBOM, so the site can be evidenced under the EU Cyber Resilience Act.

The CRA's reporting obligations apply from 11 September 2026, with full application from 11 December 2027. Manufacturers of products with digital elements must be able to produce a software bill of materials and handle vulnerabilities across a defined support period. This module is the Drupal on-ramp for that evidence.

What it does
Builds a CycloneDX 1.5 SBOM of core, contrib and custom extensions.
Maps every component to a Composer package URL — Token 8.x-1.15 becomes pkg:composer/drupal/[email protected]. These are the identifiers the Drupal security advisories and OSV feeds match on, so known vulnerabilities are recognised automatically once the SBOM lands.
Sends it to your console over HTTPS, authenticated with a licence key. Sending is opt-in and can run on cron, or on demand from the settings form.
Produces a stable serial number for an unchanged inventory, so repeat sends are recognisable as identical rather than looking like drift.
What it does not do
No data leaves your site until you enter a licence key and console URL. There is no telemetry and no phone-home.
It sends an inventory of extension names and versions. It does not read content, user data, or configuration beyond its own settings.
It is not legal advice. Verify your CRA obligations with qualified counsel.
Requirements
Drupal 10 or 11
PHP 8.1 or later
A console endpoint to receive the SBOM. A hosted account is available at proofwright.eu, and the module works standalone against any endpoint implementing the documented ingest API.
GPL-2.0-or-later.<

Activity

Tracked releases
1
Tracked since
Aug 2026
Latest release
7 hours ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Active

Releases

Version Type Release date
1.0.x-dev Dev Aug 5, 2026